CVE · High

CVE-2025-32117 — Widgetize Pages Light [widgetize-pages-light] <= 3.0 (unfixed + closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-32117 Widgetize Pages Light [widgetize-pages-light] <= 3.0 (unfixed + closed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.0 3.0 2025-04-07

CVE-2025-32117

A pair of WordPress plugins, Widgetize Pages Light and Widgets as Shortcodes, contain a security flaw that allows attackers to inject malicious code into a website. This vulnerability occurs when the plugins fail to properly filter and sanitize user input, making it possible for an attacker to trick a website visitor into executing arbitrary scripts by clicking on a link. The attack can be carried out without requiring the attacker to be authenticated, making it a potential threat to website security.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.