CVE-2025-12520 – SSRF to XSS
We discovered a Server-Side Request Forgery (SSRF) → Stored Cross-Site Scripting (XSS) vulnerability in the WordPress plugin WP Airbnb Review Slider (versions < 4.3). The issue allowed attacker-controlled HTTP responses to be fetched and stored by the plugin, resulting in persistent XSS in admin and front-end contexts. The issue has been responsibly disclosed and patched…
