Skip to content

Known CVE

Skitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Skitter Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping.

CVE-2025-28906

Medium2025CVSS 5.9CWE-79

cve2025 · wp-plugin · wp-skitter-slideshow · wordpress · wp · xss · authenticated · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website