Stored Cross-Site Scripting Vulnerability in Earnware Connect Plugin for WordPress
CVE-2025-7651
6.4MEDIUM
What is CVE-2025-7651?
The Earnware Connect plugin for WordPress contains a vulnerability that allows authenticated users with contributor-level access and above to exploit the 'ew_hasrole' shortcode. This flaw arises from inadequate input sanitization and ineffective output escaping on attributes provided by users. As a result, attackers can inject malicious web scripts into WordPress pages. These injected scripts will execute whenever a user accesses an affected page, potentially leading to significant security risks and abuse of user trust.
Affected Version(s)
Earnware Connect * <= 1.0.73