CVE-2025-13847 | PhotoFade Plugin up to 0.2.1 on WordPress Shortcode Time cross site scripting
A vulnerability classified as problematic has been found in PhotoFade Plugin up to 0.2.1 on WordPress. This issue affects some unknown processing of the component Shortcode Handler. Performing a manipulation of the argument Time results in cross site scripting.
This vulnerability is cataloged as CVE-2025-13847. It is possible to initiate the attack remotely. There is no exploit available.