CVE-2025-7651 | Earnware Connect Plugin up to 1.0.73 on WordPress Shortcode ew_hasrole cross site scripting (EUVD-2025-25069)
A vulnerability marked as problematic has been reported in Earnware Connect Plugin up to 1.0.73 on WordPress. Affected by this issue is the function ew_hasrole of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-7651. The attack may be launched remotely. There is no exploit available.