CVE-2025-8394
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Productive Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_productive_breadcrumb shortcode in all versions up to, and including, 1.1.23 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<p>Productive Style is designed to enhance our <a href="https://www.productiveminds.com/products/wordpress-themes" rel="nofollow ugc">WordPress Themes</a>. It includes Gutenberg blocks, Elementor widgets and blocks, full-site breadcrumbs, and various content features such as team members, testimonials, banner sliders, video elements, FAQs pages and sections, brand sliders, and product category slides. It also supports local hosting of Google Fonts and allows website admins to streamline full-site typography and branding options.</p>
<h4>Why Choose This plugin?</h4>
<ul>
<li>This plugin is exclusively developed for our themes, allowing website owners to refine and customize site details in line with their branding requirements. Adjust site content, colors, fonts, and backgrounds with ease.</li>
<li>Provides essential post types for seamless content creation during website development.</li>
<li>Offers tools to integrate features throughout your site, including locally hosted Google fonts.</li>
</ul>
<h4>What Types of WordPress Websites Does This Plugin Support?</h4>
<p>This plugin seamlessly integrates with WordPress. It’s translation-ready, complete with a .pot file. It fully supports Right-To-Left (RTL) languages and is compatible with multi-language sites, extending full WPML support.</p>
<p>Utilize this plugin to enhance your WordPress website with the necessary tools and features to meet your branding needs.</p>
<h3>Plugin Pages</h3>
<ul>
<li><a href="http://www.productiveminds.com/product/productive-style" rel="nofollow ugc">Complete plugin description</a></li>
<li><a href="https://demo.productiveminds.com/productive-ecommerce" rel="nofollow ugc">Live Demo</a></li>
<li><a href="http://www.productiveminds.com/support/docs/productive-style" rel="nofollow ugc">Documentation</a></li>
<li><a href="http://www.productiveminds.com/support" rel="nofollow ugc">Customer Support</a></li>
</ul>
<h3>Features Overview</h3>
<p>The highlighted features on this page are only a subset of the plugin’s features. A comprehensive feature list can be found on the <a href="http://www.productiveminds.com/product/productive-style#features" rel="nofollow ugc">plugin’s page here</a>. Check out the <a href="http://www.productiveminds.com/product/productive-style#free-vs-pro" rel="nofollow ugc">Free vs Pro section</a> for a detailed comparison of both versions.</p>
<ul>
<li>Host over 15 renowned Google fonts, such as Roboto, Open Sans, and Poppins, locally on your site.</li>
<li>Tailor website aesthetics including body colors, font choices, and backgrounds.</li>
<li>Personalize headers, footers, buttons, links, and more for cohesive branding.</li>
<li>Refine your navigation bar, menu options, and associated icons.</li>
<li>Avail structured content modules for general content, team profiles, and FAQs.</li>
</ul>
<p>The mentioned functionalities represent just a portion of the plugin’s capabilities available in either the standard or Pro version. For a complete list of features, visit the <a href="http://www.productiveminds.com/product/productive-style#features" rel="nofollow ugc">plugin’s page here</a>. For an in-depth comparison between the two versions, see the <a href="http://www.productiveminds.com/product/productive-style#free-vs-pro" rel="nofollow ugc">Free vs Pro section</a>.</p>
<h3>Attribution</h3>
<p>swiperjs, The Most Modern Mobile Touch Slider<br />
https://github.com/nolimits4web/swiper<br />
License: MIT Licensed<br />
License URL: https://github.com/nolimits4web/swiper?tab=MIT-1-ov-file</p>