CVE-2025-13308 - Application Passwords <= 0.1.3 - reflected cross-site scripting via reject_url

CVE-2025-13308 - Application Passwords <= 0.1.3 - reflected cross-site scripting via reject_url

CVE ID : CVE-2025-13308 Published : 6 Dec 2025, 6:15 a.m. | 1 hour ago Description : The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' parameter in all versions up to, and including, 0.1.3. This is due to insufficient input sanitization and output escaping on user supplied URLs, which allows javascript: URI schemes to be embedded in the reject_url parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when a user clicks the

CVE Details

Affected Product: WordPress

Source: Telegram CVE Monitor