Stored Cross-Site Scripting in Namasha by Mdesign for WordPress
CVE-2025-6537
What is CVE-2025-6537?
The Namasha By Mdesign plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting attacks. This issue arises from improper handling of the ‘playicon_title’ parameter, allowing authenticated attackers with Contributor-level access and higher to inject harmful web scripts. Once injected, these scripts are executed whenever other users visit affected pages, potentially compromising their data and interactions within the application. Proper implementation of input sanitization and output escaping is crucial to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Namasha By Mdesign * <= 1.2.00
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved