Stored Cross-Site Scripting Vulnerability in WP-PhotoNav Plugin by WordPress
CVE-2025-6383
6.4MEDIUM
What is CVE-2025-6383?
The WP-PhotoNav plugin for WordPress contains a vulnerability that allows authenticated users, including contributors, to exploit the photonav shortcode. This exploitation is made possible due to inadequate sanitization and escaping of user-supplied attributes. Attackers can inject malicious web scripts that execute when other users access affected pages, posing significant risks to website security.
Affected Version(s)
WP-PhotoNav * <= 1.2.2