CVE-2025-24673: WordPress Ketchup Shortcodes Plugin <= 0.1.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ketchup Shortcodes ketchup-shortcodes-pack allows Stored XSS.This issue affects Ketchup Shortcodes: from n/a through <= 0.1.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24673?
CVE-2025-24673 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-24673?
To fix CVE-2025-24673, update AyeCode Ltd Ketchup Shortcodes to the latest version that addresses this vulnerability, ensuring you are beyond version 0.1.2.
What type of vulnerability is CVE-2025-24673?
CVE-2025-24673 is an improper neutralization of script-related HTML tags in a web page, leading to a basic cross-site scripting (XSS) issue.
What software is affected by CVE-2025-24673?
CVE-2025-24673 affects AyeCode Ltd Ketchup Shortcodes versions from n/a through 0.1.2.
Can CVE-2025-24673 impact user data?
Yes, CVE-2025-24673 can impact user data by allowing malicious scripts to be executed in the context of a user's session.