CVE-2025-14131 | WP Widget Changer Plugin up to 1.2.5 on WordPress $_SERVER['PHP_SELF'] cross site scripting
A vulnerability labeled as problematic has been found in WP Widget Changer Plugin up to 1.2.5 on WordPress. The affected element is an unknown function. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting.
This vulnerability is listed as CVE-2025-14131. The attack may be performed from remote. There is no available exploit.