cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-scriptcase wp-scriptcase

Direction: ascending
Oct 12, 2025

WP Scriptcase # CVE-2025-8691

CVE, Research URL

CVE-2025-8691

Application

WP Scriptcase

Date
Sep 11, 2025
Research Description
The WP Scriptcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.0.0.
Status
vulnerable