MEDIUM
WEN Themes
CVE published 2026-05-07
CVE-2025-62127
A Cross-site Scripting (XSS) vulnerability exists in the WEN Logo Slider plugin for WordPress, affecting versions from n/a through 3.4.0. This issue allows for DOM-Based XSS, with a CVSS score of 5.9 and a severity of MEDIUM. Defenders responsible for WordPress environments using the WEN Logo Slider plugin should assess exposure and prioritize verification and potential updates. The vulnerability has been [truncated]