Record summary

CVE-2025-28906 has a selected CVSS score of 5.9 (medium); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thiago S.F. Skitter Slideshow wp-skitter-slideshow allows Stored XSS.This issue affects Skitter Slideshow: from n/a through <= 2.5.2.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Skitter Slideshow

Browse Thiago S.F. / Skitter Slideshowwp-skitter-slideshow

Default status: unaffected

CVE ListThrough 2.5.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSkitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site ScriptingCVSS 5.9

The Skitter Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping.

Impact

Authenticated administrators can inject stored XSS through improperly sanitized configuration parameters, potentially compromising other administrator sessions and gaining persistent control.

Remediation

Upgrade to Skitter Slideshow version 2.5.3 or later that properly sanitizes and escapes configuration inputs.

WeaknessesCWE-79
Authorsnblirwn
Template tagscvecve2025wp-pluginwp-skitter-slideshowwordpresswpxssauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

Source: ProjectDiscovery

References

3