PT-2026-1571 · WordPress · Simple User Meta Editor
Bhumividh Treloges
·
Published
2026-01-07
·
Updated
2026-01-07
·
CVE-2025-14888
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple User Meta Editor versions prior to 1.0.1
Description
The Simple User Meta Editor plugin for WordPress has a flaw that allows an attacker to inject malicious web scripts into pages viewed by users. This is due to a lack of proper sanitization and escaping of user-provided data. Specifically, the
user meta value field is susceptible to this issue. The flaw requires administrator-level access and only impacts multi-site installations or those where unfiltered html is disabled. An authenticated attacker can exploit this to execute arbitrary scripts when a user accesses an injected page.Recommendations
Update Simple User Meta Editor to version 1.0.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple User Meta Editor