CVE-2025-13835: WordPress Arconix Shortcodes plugin <= 2.1.20 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tyche Softwares Arconix Shortcodes allows Stored XSS.This issue affects Arconix Shortcodes: from n/a through 2.1.19.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Stored XSS.This issue affects Arconix Shortcodes: from n/a through <= 2.1.20.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13835?
CVE-2025-13835 is classified as a critical severity vulnerability due to its potential for allowing stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-13835?
To fix CVE-2025-13835, update the Arconix Shortcodes plugin to a version above 2.1.19.
What types of attacks can CVE-2025-13835 facilitate?
CVE-2025-13835 can facilitate stored Cross-site Scripting (XSS) attacks which could allow an attacker to inject malicious scripts.
Which versions of Arconix Shortcodes are affected by CVE-2025-13835?
CVE-2025-13835 affects all versions of Arconix Shortcodes up to and including version 2.1.19.
Who is the vendor for the software affected by CVE-2025-13835?
The vendor for the software affected by CVE-2025-13835 is Tyche Softwares.