Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 11 min 136 bronnen 2 kritiek 7 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2025-13958

MEDIUM · 5.9 CVSS Gepubliceerd:

Beschrijving NL

De YaMaps for WordPress Plugin WordPress-plug-in vóór 0.6.40 valideert en ontsnapt niet aan enkele van zijn shortcode-attributen voordat deze worden uitgevoerd in een pagina/post waar de shortcode is ingesloten, waardoor gebruikers met de inzenderrol en hoger Stored Cross-Site Scripting-aanvallen kunnen uitvoeren.

Origineel (Engels) tonen

The YaMaps for WordPress Plugin WordPress plugin before 0.6.40 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

References