CVE-2025-14145 | Niche Hero Plugin up to 1.0.5 on WordPress Shortcode spacing cross site scripting
A vulnerability classified as problematic was found in Niche Hero Plugin up to 1.0.5 on WordPress. Impacted is an unknown function of the component Shortcode Handler. Executing a manipulation of the argument spacing can lead to cross site scripting.
This vulnerability is registered as CVE-2025-14145. It is possible to launch the attack remotely. No exploit is available.