Vulnerabilities
CVE-2025-13401 - Autoptimize <= 3.1.13 - authenticated (contributor+) stored cross-site scripting
2025-12-03
0 views
admin
CVE ID : CVE-2025-13401 Published : Dec. 3, 2025, 1:52 p.m. | 29 minutes ago Description : The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes in the
🏷️ Tags
13401autoptimizeauthenticatedcontributorstoredcrossscriptingpublishedcve
More from Vulnerabilities
CVE-2025-14353 - ZIP Code Based Content Protection <= 1.0.2 - unauthenticated sql injection via '...
2026-03-07
0
CVE-2026-1902 - Hammas Calendar <= 1.5.11 - authenticated (contributor+) stored cross-site script...
2026-03-07
0
CVE-2026-1650 - MDJM Event Management <= 1.7.8.1 - missing authorization to unauthenticated arbit...
2026-03-07
0
CVE-2026-2494 - ProfileGrid <= 5.9.8.2 - cross-site request forgery to group membership request a...
2026-03-07
0
Trending
1
CVE-2025-61481: Critical Remote Code Execution Vulnerability in MikroTik RouterOS & SwitchOS
2025-10-27 • 189 views
2
CVE-2025-43939: Dell Unity OS Command Injection (High)
2025-10-30 • 148 views
3
Google disputes false claims of massive Gmail data breach
2025-10-30 • 130 views
4
Microsoft: DNS outage impacts Azure and Microsoft 365 services
2025-10-30 • 88 views
5
3.5B Accounts, 1 Critical Flaw: Meta Closes WhatsApp Data-Harvesting
2025-11-25 • 81 views