Stored Cross-Site Scripting Vulnerability in Web-Cam Plugin for WordPress
CVE-2025-6540
6.4MEDIUM
What is CVE-2025-6540?
The Web-Cam plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a lack of proper input sanitization and output escaping in the 'slug' parameter. This vulnerability permits authenticated contributors and above to inject malicious web scripts into pages. When a user accesses a compromised page, the injected scripts will execute, potentially compromising user data and site integrity.
Affected Version(s)
web-cam * <= 1.0