
CVE-2025-14851 The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode parameters in all versions up to, and including, … https://www.cve.org/CVERecord?id=CVE-2025-14851
Post summary
The YaMaps WordPress plugin is vulnerable to stored XSS via its shortcode parameters (CVE-2025-14851), with no mention of patches, exploits, or active attacks.
