Stored Cross-Site Scripting in Mmm Unity Loader Plugin for WordPress
CVE-2025-8399
6.4MEDIUM
What is CVE-2025-8399?
The Mmm Unity Loader plugin for WordPress suffers from a vulnerability that allows authenticated attackers with Contributor-level access or higher to exploit the 'attributes' parameter. Due to inadequate input sanitization and output escaping, these attackers can inject arbitrary web scripts into webpages. Consequently, when a user accesses any page where the script has been injected, it may execute, potentially compromising user data and site integrity.
Affected Version(s)
Mmm Unity Loader * <= 1.0