CVE-2025-30533: WordPress Message ticker plugin <= 9.3 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Message ticker message-ticker allows Stored XSS.This issue affects Message ticker: from n/a through <= 9.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30533?
CVE-2025-30533 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-30533?
To fix CVE-2025-30533, you should update gopiplus Message ticker to version 9.4 or later.
What impact does CVE-2025-30533 have on my website?
CVE-2025-30533 can allow attackers to execute malicious scripts in the context of users visiting your site, potentially compromising user data.
Which versions of gopiplus Message ticker are affected by CVE-2025-30533?
CVE-2025-30533 affects gopiplus Message ticker versions from n/a through 9.3.
Is my WordPress site vulnerable due to CVE-2025-30533?
Yes, if you are using the WordPress Message ticker plugin version 9.3 or earlier, your site is vulnerable to CVE-2025-30533.