🔐 CVE Alert

CVE-2025-23478

UNKNOWN 0.0

WordPress Photo Video Store plugin <= 21.07 - Reflected Cross Site Scripting (XSS) vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmsaccount Photo Video Store photo-video-store allows Reflected XSS.This issue affects Photo Video Store: from n/a through <= 21.07.

CWE CWE-79
Vendor cmsaccount
Product photo video store
Published Mar 3, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for cmsaccount photo video store

Be the first to know when new unknown vulnerabilities affecting cmsaccount photo video store are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

cmsaccount / Photo Video Store
0 ≤ 21.07

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/photo-video-store/vulnerability/wordpress-photo-video-store-plugin-21-07-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve

Credits

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program