Files
CVEs-PoC/2025/CVE-2025-4133.md
T
2025-09-29 21:09:30 +02:00

834 B

CVE-2025-4133

Description

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts when outputting them in a dashboard, which could allow users with the contributor role to perform Cross-Site Scripting attacks.

POC

Reference

Github

No PoCs found on GitHub currently.