
CVE-2025-14445 The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' custom field meta in all versions up to, and in… https://www.cve.org/CVERecord?id=CVE-2025-14445
Post summary
The text announces a stored cross‑site scripting vulnerability in the Image Hotspot WordPress plugin, affecting all versions up to the current one via the hotspot_content custom field.
