CVE-2025-50043: WordPress Code Engine plugin <= 0.3.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Code Engine allows Stored XSS. This issue affects Code Engine: from n/a through 0.3.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Code Engine code-engine allows Stored XSS.This issue affects Code Engine: from n/a through <= 0.3.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50043?
CVE-2025-50043 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-50043?
To mitigate CVE-2025-50043, you should upgrade the Code Engine to a version beyond 0.3.2.
What products are affected by CVE-2025-50043?
CVE-2025-50043 affects Jordy Meow Code Engine and the WordPress Code Engine plugin up to version 0.3.2.
What type of attack is associated with CVE-2025-50043?
CVE-2025-50043 is associated with a Stored Cross-site Scripting attack, which involves malicious scripts stored on the server.
Is user input involved in CVE-2025-50043?
Yes, CVE-2025-50043 involves improper neutralization of user input during web page generation.