{"id":"CVE-2025-5083","summary":"Amministrazione Trasparente \u003c= 9.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via print_r Function","details":"The Amministrazione Trasparente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","modified":"2026-08-12T03:51:15.130220374Z","published":"2025-08-31T04:25:48.840Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5083.json","cna_assigner":"Wordfence","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/WPGov/amministrazione-trasparente/blob/31e69c2ef42f36bca0b66d0550794d18292f5a23/settings.php#L49-L50"},{"type":"WEB","url":"https://github.com/WPGov/amministrazione-trasparente/blob/31e69c2ef42f36bca0b66d0550794d18292f5a23/settings.php#L59-L60"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset/3352443/"},{"type":"WEB","url":"https://wordpress.org/plugins/amministrazione-trasparente/#developers"},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8741bbdf-ddd9-41f7-8d22-b9350f2cf659?source=cve"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5083.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5083"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wpgov/amministrazione-trasparente","events":[{"introduced":"0"},{"last_affected":"2f4a4b64a67846ac49520a602af692f182e80dc9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"9.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v9.0.1","v9.0","v8.1.4","v8.1.3","v8.1.2","v8.1.1","v8.1","v8.0.10","v8.0.5","v8.0.2","v8.0.1","v7.2.3","v7.2.2","v7.2.1","7.2","7.1.6","7.1.5","7.1.4.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5083.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"}]}