UNKNOWN (0.0)
    Plugin

    Stored Cross-Site Scripting in Related Posts Lite Plugin

    Published Date: 10/18/2025
    CVE ID: CVE-2025-11926

    Summary

    The Related Posts Lite plugin for WordPress contains a vulnerability that allows stored Cross-Site Scripting (XSS) attacks. This vulnerability affects versions up to 1.12 and allows authenticated users with administrator-level permissions to inject malicious scripts via the plugin's admin settings.

    Vulnerability Details

    The vulnerability in the Related Posts Lite plugin stems from improper input sanitization and output escaping in its admin settings interface. This flaw permits administrators to embed arbitrary web scripts that execute when a user accesses an affected page. While this vulnerability requires administrator-level access to exploit, it is particularly concerning because the scripts are stored persistently. The issue is limited to environments where multi-site installations are in use or where the unfiltered_html capability is restricted. The vulnerability does not have a CVSS score at the moment, indicating a potential lack of severity assessment, but it still poses a risk by allowing script injection that could lead to various forms of attacks, including data theft and user session hijacking.

    Recommendations

    To mitigate this vulnerability, it is crucial to ensure that all input fields within the Related Posts Lite plugin settings are properly sanitized and that output functions are escaped. Administrators should enable filtering for all user roles whenever possible and audit usage of the unfiltered_html capability. Additionally, limit administrator access to only trusted personnel and employ a thorough review of plugin settings on multi-site installations.

    Available Fixes

    Last Updated: 10/19/2025
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2025 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More