
Cloud Vulnerability DB
A community-led vulnerabilities database
The XX2WP Integration Tools plugin for WordPress contains a Stored Cross-Site Scripting vulnerability (CVE-2025-11857) discovered in versions up to and including 1.9.9. The vulnerability was disclosed on October 17, 2025, and affects the 'mxpfb2wpdisplay_embed' shortcode functionality (Wordfence).
The vulnerability exists due to improper sanitization of user input and output of the 'postid' parameter in the 'mxpfb2wpdisplayembed' shortcode. The issue has been assigned a CVSS v3.1 base score of 6.4 (Medium), indicating moderate severity (NVD).
This vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages. These malicious scripts will execute whenever a user accesses an affected page, potentially leading to unauthorized actions being performed on behalf of other users viewing the compromised content (NVD).
Website administrators running affected versions of the XX2WP Integration Tools plugin should update to a patched version when available. In the meantime, it is recommended to restrict access to contributor roles and monitor for suspicious shortcode usage (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."