Cross-site Scripting Vulnerability in CK MacLeod Category Featured Images Extended
CVE-2025-57920
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2025
What is CVE-2025-57920?
This vulnerability in CK MacLeod's Category Featured Images Extended plugin allows for stored Cross-site Scripting (XSS), where attackers can inject malicious scripts that are stored on the server and executed whenever users load affected pages. This can lead to data theft, unauthorized actions, and compromised user sessions. The vulnerability spans from version n/a through 1.52, posing a significant risk for web applications using this plugin.
Affected Version(s)
Category Featured Images Extended 0 <= 1.52