CVE-2025-8290

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>This plugin creates a &#8220;Sub Pages&#8221; Widget and also a dynamically generated &#8220;sub_page&#8221; shortcode with different parameters passing in it.Please find option available with this plugin for both &#8220;Sub Pages&#8221; Widget and &#8220;sub_page&#8221; shortcode.</p> <p>The plugin provides a shortcode generator page(Option Page) in which dynamic shortcode is generated simultaneously when you select your options from the options field. The selected values are passed as a shortcode parameters and everytime you visit the page you can generate the shortcode you want.</p> <h4>Key Features</h4> <p>Below are the options for displaying subpage if exists for that particular parent page.</p> <ul> <li>Title</li> <li>Displaying Sub Pages using a Sorting Order option.</li> </ul> <p>Below are the options to add effect in the parent pages display when subpages are not available to display.</p> <ul> <li>Displaying parent page as per Sorting Criteria </li> <li>Page Exclusion, to not show the title of specific pages. </li> <li>Depth Level, </li> <li>Parent Sort Order, displaying parent pages title link using a Sorting Order option.</li> </ul> <p>You can Copy the Dynamic Shortcode and paste where you want to display subpages or parent pages list.</p> <p>Dynamic Shortcode:<br /> e.g: [sub_page title=&#8217;Pages&#8217; sort_order=&#8217;DESC&#8217; sort_by_values=&#8217;ID&#8217; exclude_page_id=&#8217;13&#8217; depth=&#8217;2&#8242; sort_order_parent=&#8217;DESC&#8217; ]</p> <p>Note: This plugin will list the subpages for the current page being displayed, but if their is no childpage(subpage) for the current displaying page then it will display list of all the parent pages. If you don&#8217;t want to display some of the parent pages then also their is a feature in the plugin.</p> <h3>Translation available in following languages</h3> <ol> <li>English</li> <li>French</li> <li>Spanish</li> <li>Chinese</li> </ol>
WordPress Plugin DirectoryWordPress Plugin Directory
12.8K