CVE-2025-30983: WordPress Card flip image slideshow plugin <= 1.5 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Card flip image slideshow allows DOM-Based XSS. This issue affects Card flip image slideshow: from n/a through 1.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Card flip image slideshow card-flip-image-slideshow allows DOM-Based XSS.This issue affects Card flip image slideshow: from n/a through <= 1.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30983?
CVE-2025-30983 is classified as a Cross-site Scripting (XSS) vulnerability that can lead to significant security risks if exploited.
How do I fix CVE-2025-30983?
To fix CVE-2025-30983, upgrade the Gopiplus Card flip image slideshow plugin to version 1.5 or later.
What impact does CVE-2025-30983 have on my website?
CVE-2025-30983 can allow attackers to execute arbitrary JavaScript in users' browsers, potentially compromising user data and web sessions.
Which versions are affected by CVE-2025-30983?
CVE-2025-30983 affects all versions of Gopiplus Card flip image slideshow up to and including version 1.5.
Is CVE-2025-30983 specific to WordPress installations?
CVE-2025-30983 affects both the Gopiplus and WordPress implementations of the Card flip image slideshow plugin.