Stored Cross-Site Scripting in Namasha by Mdesign for WordPress
CVE-2025-6537

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 June 2025

What is CVE-2025-6537?

The Namasha By Mdesign plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting attacks. This issue arises from improper handling of the ‘playicon_title’ parameter, allowing authenticated attackers with Contributor-level access and higher to inject harmful web scripts. Once injected, these scripts are executed whenever other users visit affected pages, potentially compromising their data and interactions within the application. Proper implementation of input sanitization and output escaping is crucial to mitigate this risk.

Affected Version(s)

Namasha By Mdesign * <= 1.2.00

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gilang Asra Bilhadi
.
CVE-2025-6537 : Stored Cross-Site Scripting in Namasha by Mdesign for WordPress