CVE-2025-26980: WordPress Wired Impact Volunteer Management plugin <= 2.5 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Stored XSS.This issue affects Wired Impact Volunteer Management: from n/a through <= 2.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26980?
CVE-2025-26980 has been classified as a high-severity vulnerability due to its potential impact on user data through Stored XSS.
How do I fix CVE-2025-26980?
To fix CVE-2025-26980, update Wired Impact Volunteer Management to version 2.6 or later.
What type of vulnerability is CVE-2025-26980?
CVE-2025-26980 is a Stored Cross-site Scripting (XSS) vulnerability.
Which versions are affected by CVE-2025-26980?
CVE-2025-26980 affects Wired Impact Volunteer Management versions up to and including 2.5.
What impact does CVE-2025-26980 have?
The impact of CVE-2025-26980 includes the possibility of attackers injecting malicious scripts into web pages viewed by users.