Cross-Site Scripting Vulnerability in Doliconnect by ptibogxiv
CVE-2025-53574

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-53574?

The Doliconnect plugin developed by ptibogxiv is vulnerable to a Cross-Site Scripting (XSS) flaw, allowing attackers to inject malicious scripts through manipulated input fields. This vulnerability could lead to unauthorized access and data exposure, affecting users who interact with the affected versions of Doliconnect including n/a and up to 9.3.2. Website administrators using this plugin should take immediate action to mitigate potential risks by applying recommended security patches or updating to a secure version.

Affected Version(s)

Doliconnect <= n/a

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien | Patchstack Bug Bounty Program
.