WordPress · Shopbuilder Wordpress Plugin · CVE-2025-13456
**Name of the Vulnerable Software and Affected Versions**
ShopBuilder WordPress plugin versions prior to 3.2.2
**Description**
The ShopBuilder WordPress plugin does not properly sanitize and escape a parameter before outputting it, resulting in a Reflected Cross-Site Scripting issue. This could potentially be used to target users with high privileges, such as administrators.
**Recommendations**
Update to ShopBuilder WordPress plugin version 3.2.2 or later.