CVE-2025-49858: WordPress Arconix Shortcodes plugin <= 2.1.17 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Stored XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.17.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Stored XSS.This issue affects Arconix Shortcodes: from n/a through <= 2.1.17.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49858?
CVE-2025-49858 has a high severity rating due to its potential for allowing stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-49858?
To fix CVE-2025-49858, you should update Arconix Shortcodes to at least version 2.1.18 or later.
What causes CVE-2025-49858?
CVE-2025-49858 is caused by improper neutralization of user input during web page generation, allowing for XSS vulnerabilities.
Who is affected by CVE-2025-49858?
CVE-2025-49858 affects users of Arconix Shortcodes versions n/a through 2.1.17.
What are the potential impacts of CVE-2025-49858?
The potential impacts of CVE-2025-49858 include unauthorized access to user data, session hijacking, and the spread of malware.