🔐 CVE Alert

CVE-2025-49063

UNKNOWN 0.0

WordPress BaiduXZH Submit(百度熊掌号) plugin <= 1.4.6 - Reflected Cross Site Scripting (XSS) vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in i3geek BaiduXZH Submit(百度熊掌号) i3geek-baiduxzh allows Reflected XSS.This issue affects BaiduXZH Submit(百度熊掌号): from n/a through <= 1.4.6.

CWE CWE-79
Vendor i3geek
Product baiduxzh submit(百度熊掌号)
Published Aug 14, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for i3geek baiduxzh submit(百度熊掌号)

Be the first to know when new unknown vulnerabilities affecting i3geek baiduxzh submit(百度熊掌号) are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

i3geek / BaiduXZH Submit(百度熊掌号)
0 ≤ 1.4.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/i3geek-baiduxzh/vulnerability/wordpress-baiduxzh-submit-plugin-1-4-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve

Credits

Nguyen Xuan Chien | Patchstack Bug Bounty Program