CVE-2025-14887 | wpcommerz twinklesmtp Plugin up to 1.03 on WordPress cross site scripting
A vulnerability, which was classified as problematic, has been found in wpcommerz twinklesmtp Plugin up to 1.03 on WordPress. This affects an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-14887. It is possible to initiate the attack remotely. There is no exploit available.