CVE-2025-13705 | Custom Frames Plugin up to 1.0.1 on WordPress Shortcode customframe Class cross site scripting (EUVD-2025-203222)
A vulnerability marked as problematic has been reported in Custom Frames Plugin up to 1.0.1 on WordPress. The impacted element is the function customframe of the component Shortcode Handler. This manipulation of the argument Class causes cross site scripting.
This vulnerability is tracked as CVE-2025-13705. The attack is possible to be carried out remotely. No exploit exists.