PT-2025-30647 · WordPress · Taeggie Feed

Published

2025-07-24

·

Updated

2025-07-24

·

CVE-2025-6382

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Taeggie Feed plugin for WordPress versions up to and including 0.1.10
Description The Taeggie Feed plugin for WordPress is susceptible to Stored Cross-Site Scripting through the plugin’s taeggie-feed shortcode. The render() method incorporates user-provided data from the name attribute directly into a <script> tag, including within the id attribute and the jQuery.getScript() function, without adequate sanitization. This allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which will execute upon user access.
Recommendations Update the Taeggie Feed plugin to a version beyond 0.1.10.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-6382

Affected Products

Taeggie Feed