Ad

CVE-2025-15363

NONE
Updated Mar 18, 2026
WordPress
Parameter Value
Affected Versions before 2.0.10
Vendor WordPress
Public PoC No

The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks under certain server configurations.