๐Ÿ” CVE Alert

CVE-2025-15690

MEDIUM 6.8

Content Mask 1.7.1 - 1.8.5.5 - Contributor+ Stored XSS via Post Scripts and Styles

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before outputting it in the pages it generates, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against any user viewing or previewing the affected page. The Content Mask WordPress plugin before 1.8.5.6's option to restrict its use by role does not prevent this.

Vendor unknown
Product content mask
Published Sep 9, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown content mask

Be the first to know when new medium vulnerabilities affecting unknown content mask are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Content Mask
1.7.1 < 1.8.5.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/bb49823c-16f1-4cce-a212-ae2aa7ea5730/

Credits

Andrea Fiocchi WPScan