CVE-2025-49889 | imaprogrammer Custom Comment Plugin up to 2.1.6 on WordPress cross site scripting
A vulnerability was found in imaprogrammer Custom Comment Plugin up to 2.1.6 on WordPress. It has been declared as problematic. This affects an unknown function. Executing manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2025-49889. The attack can be executed remotely. There is not any exploit available.