Cross-site Scripting Vulnerability in XmasB Quotes Plugin by WordPress
CVE-2025-53220
7.1HIGH
What is CVE-2025-53220?
The XmasB Quotes plugin for WordPress is susceptible to a Cross-site Scripting (XSS) vulnerability due to improper neutralization of user input during web page generation. This vulnerability allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser when they visit a compromised page. Users of the affected plugin versions should take immediate action to mitigate this risk and protect their websites against potential exploitation.
Affected Version(s)
XmasB Quotes <= 1.6.1