PT-2025-53847 · WordPress · Advance Wp Query Search Filter
Yevgen Goncharuk
·
Published
2025-12-30
·
Updated
2025-12-30
·
CVE-2025-14313
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Advance WP Query Search Filter WordPress plugin versions through 1.0.10
Description
The software does not properly sanitize and escape a parameter before displaying it, potentially leading to a Reflected Cross-Site Scripting issue. This could be leveraged against users with high privileges, such as administrators. The issue involves improper handling of user-supplied input, which can be reflected back into the web page without adequate sanitization. This allows an attacker to inject malicious scripts into the page, which are then executed by the victim's browser.
Recommendations
Update to a version beyond 1.0.10.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Advance Wp Query Search Filter