CVE-2025-13894 | CSV Sumotto Plugin up to 1.0 on WordPress $_SERVER['PHP_SELF'] cross site scripting (EUVD-2025-201516)
A vulnerability, which was classified as problematic, was found in CSV Sumotto Plugin up to 1.0 on WordPress. This impacts an unknown function. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting.
This vulnerability is traded as CVE-2025-13894. The attack may be launched remotely. There is no exploit available.