Stored Cross-Site Scripting Vulnerability in Partnerský systém Martinus Plugin for WordPress
CVE-2025-7661
6.4MEDIUM
What is CVE-2025-7661?
The Partnerský systém Martinus plugin for WordPress is susceptible to a Stored Cross-Site Scripting attack due to improper input sanitization and output escaping of user-supplied attributes within the 'martinus' shortcode. This vulnerability allows authenticated attackers with contributor access or higher to insert malicious JavaScript code into web pages. These scripts are executed whenever a user navigates to the compromised page, posing a serious threat to site security and user data.
Affected Version(s)
Partnerský systém Martinus * <= 1.7.1