Stored Cross-Site Scripting Vulnerability in Spotify Embed Creator Plugin for WordPress
CVE-2025-9879

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
12 September 2025

What is CVE-2025-9879?

The Spotify Embed Creator plugin for WordPress exposes users to a Stored Cross-Site Scripting (XSS) vulnerability via its 'spotify' shortcode. This issue arises from inadequate input sanitization and output escaping on user-supplied attributes, allowing authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. These scripts can execute on pages viewed by other users, leading to potential data compromise or site manipulation.

Affected Version(s)

Spotify Embed Creator * <= 1.0.5

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-9879 : Stored Cross-Site Scripting Vulnerability in Spotify Embed Creator Plugin for WordPress