
CVE-2025-1794 The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all versions up to, and including, 3.6.0 due to insuffic… https://www.cve.org/CVERecord?id=CVE-2025-1794
Post summary
The AM LottiePlayer plugin is vulnerable to stored XSS through uploaded SVG files, affecting all versions up to 3.6.0; no patch or exploit details are provided.
