CVE-2025-13848 | STM Gallery Plugin up to 1.9 on WordPress Shortcode composicion cross site scripting
A vulnerability labeled as problematic has been found in STM Gallery Plugin up to 1.9 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. The manipulation of the argument composicion results in cross site scripting.
This vulnerability is identified as CVE-2025-13848. The attack can be executed remotely. There is not any exploit available.