Stored Cross-Site Scripting in Namasha by Mdesign for WordPress
CVE-2025-6537
6.4MEDIUM
What is CVE-2025-6537?
The Namasha By Mdesign plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting attacks. This issue arises from improper handling of the ‘playicon_title’ parameter, allowing authenticated attackers with Contributor-level access and higher to inject harmful web scripts. Once injected, these scripts are executed whenever other users visit affected pages, potentially compromising their data and interactions within the application. Proper implementation of input sanitization and output escaping is crucial to mitigate this risk.
Affected Version(s)
Namasha By Mdesign * <= 1.2.00