Stored Cross-Site Scripting Vulnerability in Mixtape Plugin for WordPress
CVE-2025-9860
6.4MEDIUM
What is CVE-2025-9860?
The Mixtape plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through its 'mixtape' shortcode, affecting all versions up to and including 1.1. This vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes. Authenticated attackers with contributor-level access or higher can exploit this flaw to inject malicious web scripts into pages. These scripts execute whenever a user accesses the compromised page, potentially leading to session hijacking or other types of web-based attacks.
Affected Version(s)
Mixtape * <= 1.1