MEDIUM
tymotey
CVE published 2026-09-02
CVE-2025-7963
The Easy Waveform Player plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2. This is due to insufficient input sanitization and output escaping, allowing authenticated attackers with Contributor-level access and above to inject arbitrary web scripts. These scripts will execute when a user accesses [truncated]