Medium severity6.1NVD Advisory· Published Aug 16, 2025· Updated Jun 17, 2026
CVE-2025-8113
CVE-2025-8113
Description
The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
40+ 1 more
- (no CPE)range: 0
- cpe:2.3:a:shopfiles:ebook_store:*:*:*:*:*:wordpress:*:*range: <5.8015
<5.8015+ 1 more
- (no CPE)range: <5.8015
- (no CPE)
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/752908b4-7d05-476f-8920-1d0e58fc2983/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.