CVE-2025-30991: WordPress Premium Packages plugin <= 6.0.6 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Premium Packages allows Stored XSS. This issue affects Premium Packages: from n/a through 6.0.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Stored XSS.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30991?
CVE-2025-30991 is classified as a high severity vulnerability due to its potential for Stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-30991?
To fix CVE-2025-30991, update the Shahjada Premium Packages to version 6.0.3 or later, which addresses the XSS vulnerability.
What versions are affected by CVE-2025-30991?
CVE-2025-30991 affects all versions of Shahjada Premium Packages up to and including version 6.0.2.
Can CVE-2025-30991 lead to data theft?
Yes, CVE-2025-30991 can allow attackers to execute scripts in a victim's browser, potentially leading to data theft.
Is CVE-2025-30991 easy to exploit?
CVE-2025-30991 can be exploited easily if proper input validation is not implemented in web applications.