CVE-2025-4170 | Xavins Review Ratings Plugin up to 1.4.0 on WordPress shortcode xrr cross site scripting
A vulnerability was found in Xavins Review Ratings Plugin up to 1.4.0 on WordPress. It has been classified as problematic. This affects the function xrr of the component shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-4170. It is possible to initiate the attack remotely. There is no exploit available.