CVE-2025-54746: WordPress Shortcode Redirect Plugin <= 1.0.02 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cartpauj Shortcode Redirect allows Stored XSS. This issue affects Shortcode Redirect: from n/a through 1.0.02.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cartpauj Shortcode Redirect shortcode-redirect allows Stored XSS.This issue affects Shortcode Redirect: from n/a through <= 1.0.02.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54746?
CVE-2025-54746 is a high severity vulnerability due to its potential for stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-54746?
To fix CVE-2025-54746, update the WordPress Shortcode Redirect plugin to a version higher than 1.0.02.
What software is affected by CVE-2025-54746?
CVE-2025-54746 affects the WordPress Shortcode Redirect plugin, specifically versions up to and including 1.0.02.
What kind of vulnerability is CVE-2025-54746?
CVE-2025-54746 is a Cross-site Scripting (XSS) vulnerability that results from improper neutralization of input during web page generation.
Can CVE-2025-54746 lead to other security issues?
Yes, CVE-2025-54746 can lead to unauthorized actions on behalf of users, data theft, and website defacement due to stored XSS attacks.