Stored Cross-Site Scripting in Optio Dentistry Plugin for WordPress
CVE-2025-9853
6.4MEDIUM
What is CVE-2025-9853?
The Optio Dentistry plugin for WordPress contains a vulnerability that allows authenticated attackers with contributor-level access and above to perform Stored Cross-Site Scripting (XSS). This occurs due to improper sanitization and escaping of user-supplied input within the plugin's 'optio-lightbox' shortcode. As a result, attackers can inject malicious scripts that execute when other users access the affected pages, potentially compromising user data and site integrity.
Affected Version(s)
Optio Dentistry * <= 2.2