CVE-2025-10194 | Shortcode Button Plugin up to 1.1.9 on WordPress cross site scripting
A vulnerability labeled as problematic has been found in Shortcode Button Plugin up to 1.1.9 on WordPress. This impacts the function Button of the component Shortcode Handler. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2025-10194. It is possible to launch the attack remotely. No exploit is available.