In Football Pool plugin for WordPress versions up to and including 2.12.4 a medium severity vulnerability CVE-2025-5490 was detected. This vulnerability allows authenticated attackers with Administrator-level access and above to inject arbitrary web scripts into admin settings, leading to Stored Cross-Site Scripting (XSS) attacks in multi-site installations or setups where the unfiltered_html capability is disabled. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5490.
WordPress: Stored XSS via Admin Settings in Football Pool Plugin
by the Hossted team
19.06.2025