CVE-2025-1524 – Ultimate Dashboard < 3.8.6 – Stored XSS to Admin Creation – POC

CVE-2025-1524 – Ultimate Dashboard < 3.8.6 – Stored XSS to Admin Creation – POC

The Ultimate Dashboard plugin is a popular tool for customizing the WordPress admin dashboard, used by site owners and developers to enhance the client experience with personalized widgets, custom admin pages, and visual tweaks. However, in versions prior to 3.8.6, the plugin was affected by a Stored Cross-Site Scripting (XSS) vulnerability that could lead to privilege escalation, including unauthorized admin account creation.

This vulnerability, tracked as CVE-2025-1524, represents a critical example of how seemingly innocuous customization features can become attack vectors when proper sanitization is not enforced.

Plugin Security Certification (PSC-2025-64562): “Fluent Forms PRO” – Version 6.0.1: Use Forms with Enhanced Security

Plugin Security Certification (PSC-2025-64562): “Fluent Forms PRO” – Version 6.0.1: Use Forms with Enhanced Security

Redux Framework is a robust and developer-centric options framework for WordPress, designed to streamline and simplify theme and plugin development. Instead of reinventing the wheel with each project, Redux provides a scalable, extensible foundation for building powerful admin panels using a single, well-documented configuration file. Supporting a wide array of field types, integrated Google Fonts, compiler hooks, and validation mechanisms, Redux is a complete toolkit built for innovation.

With full responsiveness and WordPress-native integration, Redux accelerates development without compromising code quality. It enables developers to build powerful options panels faster, while also maintaining structured, secure, and maintainable code. Redux has undergone extensive security auditing and proudly holds the Plugin Security Certification (PSC-2025-64562) from CleanTalk, ensuring a secure development experience.

CVE-2025-1523 – Ultimate Dashboard < 3.8.6 – Stored XSS to Admin Creation – POC

CVE-2025-1523 – Ultimate Dashboard < 3.8.6 – Stored XSS to Admin Creation – POC

The Ultimate Dashboard plugin is a popular tool for customizing the WordPress admin dashboard, used by site owners and developers to enhance the client experience with personalized widgets, custom admin pages, and visual tweaks. However, in versions prior to 3.8.6, the plugin was affected by a Stored Cross-Site Scripting (XSS) vulnerability that could lead to privilege escalation, including unauthorized admin account creation.

This vulnerability, tracked as CVE-2025-1523, represents a critical example of how seemingly innocuous customization features can become attack vectors when proper sanitization is not enforced.

CVE-2024-10144 – Photo Gallery, Images, Slider in Rbs Image Gallery – Stored XSS to Admin Creation (Contributor+) – POC

CVE-2024-10144 – Photo Gallery, Images, Slider in Rbs Image Gallery – Stored XSS to Admin Creation (Contributor+) – POC

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin is a widely used tool for managing and displaying galleries, sliders, and images within WordPress websites. This plugin offers a variety of features to enhance the visual experience of WordPress sites, with over 50,000 active installations. However, a critical security vulnerability—CVE-2024-10144—has been discovered, allowing attackers to inject malicious JavaScript (JS) code. This vulnerability enables attackers to escalate their privileges, resulting in the potential creation of an admin account through a stored XSS attack. This vulnerability exposes sites to a range of malicious activities, including unauthorized access and potential data breaches.

CVE-2024-10107 – Giveaways and Contests by RafflePress – Stored XSS to JS Backdoor Creation – POC

CVE-2024-10107 – Giveaways and Contests by RafflePress – Stored XSS to JS Backdoor Creation – POC

The Giveaways and Contests by RafflePress plugin is a popular tool used by WordPress site owners to manage and run contests, sweepstakes, and giveaways. With over 30,000 active installations, it allows users to boost engagement and traffic by offering incentives to participants. However, a critical vulnerability—CVE-2024-100107—was discovered during testing, which exposes the plugin to a Stored Cross-Site Scripting (XSS) attack. This vulnerability allows malicious actors to inject and execute JavaScript code, enabling them to potentially gain unauthorized access to the site and create backdoors that could compromise the entire platform.

CVE-2024-13207 – Widget for Social Page Feeds < 6.4.2 – Stored XSS to Backdoor Creation – POC

CVE-2024-13207 – Widget for Social Page Feeds < 6.4.2 – Stored XSS to Backdoor Creation – POC

In April 2024, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the popular WordPress plugin Widget for Social Page Feeds (formerly known as “Facebook Page Like Widget”). This plugin is installed on over 80,000 WordPress sites and is widely used to display Facebook page feeds in sidebars and other widget areas. The vulnerability, assigned CVE-2024-13207, affects all plugin versions below 6.4.2 and can allow attackers to inject malicious JavaScript, potentially leading to full site compromise.

CVE-2024-13610 – Simple Social Media Share Buttons < 6.0.0 – Stored XSS to Backdoor Creation – POC

CVE-2024-13610 – Simple Social Media Share Buttons < 6.0.0 – Stored XSS to Backdoor Creation – POC

In early 2024, a security flaw was identified in the popular WordPress plugin Simple Social Media Share Buttons, used on thousands of websites to enhance social media engagement. The vulnerability, now tracked as CVE-2024-13610, allows attackers to inject persistent JavaScript (Stored XSS) into the admin panel via the YouTube Channel ID field inside the widget settings. In the worst-case scenario, this could lead to the creation of backdoor admin accounts, full site compromise, or even malware distribution to site visitors.

CVE-2025-1203 – Meta Slider – Stored XSS to Backdoor Creation – POC

CVE-2025-1203 – Meta Slider – Stored XSS to Backdoor Creation – POC

Meta Slider is a widely used WordPress plugin that helps users create image sliders, carousels, and other content displays. With over 600,000 installations, the plugin is a popular choice among developers and website owners for its ease of use and flexibility. However, a serious security flaw—CVE-2025-1203—has been discovered in Meta Slider, which allows malicious users to inject and execute JavaScript through a Stored Cross-Site Scripting (XSS) attack. This vulnerability enables attackers to potentially create backdoors on WordPress sites, leading to full administrative control of the site.

CVE-2025-1762 – Event Tickets with Ticket Scanner <= 2.5.4 – Arbitrary Tickets Deletion via CSRF – POC

CVE-2025-1762 – Event Tickets with Ticket Scanner <= 2.5.4 – Arbitrary Tickets Deletion via CSRF – POC

Cross-Site Request Forgery (CSRF) is a type of web security vulnerability that allows an attacker to execute unauthorized actions on behalf of an authenticated user. In the case of the Event Tickets with Ticket Scanner plugin (version <= 2.5.4), a CSRF vulnerability has been discovered, allowing attackers to delete all tickets without proper authorization.