First published: Thu Jan 09 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hccoder – Sándor Fodor Better User Shortcodes allows Reflected XSS.This issue affects Better User Shortcodes: from n/a through 1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sándor Fodor Better User Shortcodes | <=1.0 | |
WordPress Better User Shortcodes Plugin | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-22594 is considered high due to its ability to enable reflected cross-site scripting attacks.
To fix CVE-2025-22594, update the Better User Shortcodes plugin to a version above 1.0, or implement input validation and output encoding.
CVE-2025-22594 affects users of the Better User Shortcodes plugin version 1.0 and earlier.
CVE-2025-22594 is classified as a reflected cross-site scripting (XSS) vulnerability.
Yes, CVE-2025-22594 can potentially lead to data breaches if exploited, allowing attackers to execute scripts in a user's browser.