PT-2025-38692 · WordPress · Markup Markdown

Bob Matyas

·

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-9541

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Markup Markdown WordPress plugin versions prior to 3.20.10
Description The plugin allows links to contain JavaScript, potentially enabling users with contributor or higher roles to carry out Stored Cross-Site Scripting attacks.
Recommendations Update the Markup Markdown WordPress plugin to version 3.20.10 or later.

Exploit

Fix

Related Identifiers

CVE-2025-9541

Affected Products

Markup Markdown