Cross-site Scripting Vulnerability in User Notes Plugin by Cartpauj
CVE-2025-60136
5.9MEDIUM
What is CVE-2025-60136?
A Cross-site Scripting (XSS) vulnerability exists in the User Notes plugin produced by Cartpauj, allowing attackers to inject malicious scripts into user notes. This can lead to stored XSS, potentially compromising user data and session information. The vulnerability affects all versions from n/a through 1.0.2, highlighting the importance of patching and securing web applications against such attacks to protect both the integrity of user data and the overall security of WordPress sites.
Affected Version(s)
User Notes <= 1.0.2