6.4
CVSSv3

CVE-2025-5532

CVSSv4: NA | CVSSv3: 6.4 | CVSSv2: NA | VMScore: 740 | EPSS: 0.00032 | KEV: Not Included
Published: 04/06/2025 Updated: 04/06/2025

Vulnerability Summary

Stored XSS Vulnerability in Campus Directory WordPress Plugin via Shortcode Attributes

The Campus Directory plugin for WordPress contains a Stored Cross-Site Scripting vulnerability through its 'emd_mb_meta' shortcode in versions up to 1.9.0. The vulnerability stems from inadequate input sanitization and output escaping of user-supplied attributes. Authenticated attackers with contributor-level or higher permissions can inject malicious web scripts that will execute when other users access the compromised pages.

Vulnerable Product Search on Vulmon Subscribe to Product

emarket-design campus directory – faculty, staff & student directory plugin for wordpress