CVE-2025-60133: WordPress PE Easy Slider Plugin <= 1.1.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DJ-Extensions.com PE Easy Slider allows Stored XSS. This issue affects PE Easy Slider: from n/a through 1.1.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DJ-Extensions.com PE Easy Slider pe-easy-slider allows Stored XSS.This issue affects PE Easy Slider: from n/a through <= 1.1.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60133?
CVE-2025-60133 is considered a high severity vulnerability due to the risk of stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-60133?
To fix CVE-2025-60133, update the PE Easy Slider plugin to version 1.1.1 or later as recommended by the vendor.
What software is affected by CVE-2025-60133?
CVE-2025-60133 affects versions of DJ-Extensions PE Easy Slider up to and including 1.1.0.
What kind of vulnerability is CVE-2025-60133?
CVE-2025-60133 is a cross-site scripting (XSS) vulnerability that allows for the injection of malicious scripts.
How can CVE-2025-60133 impact my website?
CVE-2025-60133 can allow attackers to execute scripts in the context of a user's browser, potentially compromising user data and site integrity.