CVE-2025-12823: CSV to SortTable <= 4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
The CSV to SortTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csv' shortcode in all versions up to, and including, 4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12823?
CVE-2025-12823 is considered a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2025-12823?
To fix CVE-2025-12823, update the CSV to SortTable plugin to version 4.3 or later, which resolves the input sanitization issues.
Who is affected by CVE-2025-12823?
CVE-2025-12823 affects all versions of the CSV to SortTable plugin and WordPress versions up to and including 4.2.
What kind of attacks can be executed using CVE-2025-12823?
CVE-2025-12823 allows authenticated users to execute stored cross-site scripting attacks which can lead to site compromise.
Is CVE-2025-12823 easily exploitable?
Exploitation of CVE-2025-12823 requires authenticated access to the WordPress site, which may limit its overall risk.