Stored Cross-Site Scripting in Azurecurve BBCode Plugin for WordPress
CVE-2025-8398
6.4MEDIUM
What is CVE-2025-8398?
The Azurecurve BBCode plugin for WordPress contains a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping on user-supplied attributes within its 'url' shortcode. This weakness enables authenticated attackers with contributor-level access or higher to inject malicious web scripts into pages. When these pages are accessed by other users, the injected scripts execute, potentially compromising user data and site integrity.
Affected Version(s)
azurecurve BBCode * <= 2.0.4