CVE

CVE-2025-5585 — SiteOrigin Widgets Bundle < 1.69.0 - Contributor+ Stored XSS via `data-url` DOM Element Attribute

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-5585 SiteOrigin Widgets Bundle < 1.69.0 - Contributor+ Stored XSS via `data-url` DOM Element Attribute Unknown < 1.69.0 1.69.0

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.