WordPress Review Disclaimer plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability
CVE-2025-67628

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 December 2025

What is CVE-2025-67628?

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AMP-MODE Review Disclaimer review-disclaimer allows Stored XSS.This issue affects Review Disclaimer: from n/a through <= 2.0.3.

Affected Version(s)

Review Disclaimer <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Nur Ibnu Hubab | Patchstack Bug Bounty Program
.
CVE-2025-67628 : Cross-Site Scripting Vulnerability in Review Disclaimer Plugin by WordPress