The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks under certain server configurations.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Berkux
Berkux get Use Apis Wordpress Wordpress wordpress |
|
| Vendors & Products |
Berkux
Berkux get Use Apis Wordpress Wordpress wordpress |
Wed, 18 Mar 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks under certain server configurations. | |
| Title | Get Use APIs < 2.0.10 - Contributor+ Stored XSS | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-03-18T06:00:09.938Z
Reserved: 2025-12-30T13:51:48.843Z
Link: CVE-2025-15363
No data.
Status : Received
Published: 2026-03-18T07:16:21.187
Modified: 2026-03-18T07:16:21.187
Link: CVE-2025-15363
No data.
OpenCVE Enrichment
Updated: 2026-03-18T10:41:47Z
Weaknesses
No weakness.