CVE-2025-13840 | BUKAZU Search Widget Plugin up to 3.3.2 on WordPress Shortcode bukazu_search cross site scripting
A vulnerability was found in BUKAZU Search Widget Plugin up to 3.3.2 on WordPress. It has been classified as problematic. This vulnerability affects the function bukazu_search of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2025-13840. The attack can be initiated remotely. There is not any exploit available.