CVE-2025-13843 | VigLink SpotLight by ShortCode Plugin up to 1.0.a on WordPress Shortcode spotlight float cross site scripting
A vulnerability, which was classified as problematic, has been found in VigLink SpotLight by ShortCode Plugin up to 1.0.a on WordPress. This affects the function spotlight of the component Shortcode Handler. Performing manipulation of the argument float results in cross site scripting.
This vulnerability is identified as CVE-2025-13843. The attack can be initiated remotely. There is not any exploit available.