HIGH
Themesgrove
CVE published 2026-01-07
CVE-2025-46494
A Cross-site Scripting (XSS) vulnerability exists in WidgetKit Pro, a WordPress plugin, from version n/a through 1.13.1. This issue allows for Reflected XSS attacks. The CVE record was published on 2026-01-07T13:15:43.423Z and has not been modified since then. The NVD entry is currently Deferred. Defenders should verify exposure and assess potential impact. The vulnerability allows for Reflected XSS attac [truncated]