
CVE-2025-12448 The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in all versio… https://www.cve.org/CVERecord?id=CVE-2025-12448
Post summary
The CVE-2025-12448 vulnerability in the Smartsupp WordPress plugin is a stored XSS via the 'code' parameter; no PoC, exploit, or patch details are provided.
