In Optio Dentistry plugin for WordPress versions up to and including 2.2 a medium severity vulnerability CVE-2025-9853 was detected. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts via the ‘optio-lightbox’ shortcode, which will execute whenever a user accesses the affected page. To address this issue, users should upgrade Optio Dentistry plugin to versions 2.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-9853.
WordPress: Stored Cross-Site Scripting via ‘optio-lightbox’ Shortcode in Optio Dentistry Plugin
by the Hossted team
08.09.2025