CVE-2025-9857 | Heateor Login Plugin up to 1.1.9 on WordPress Shortcode Heateor_Facebook_Login cross site scripting (EUVD-2025-27520)
A vulnerability classified as problematic has been found in Heateor Login Plugin up to 1.1.9 on WordPress. Affected by this vulnerability is the function Heateor_Facebook_Login of the component Shortcode Handler. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2025-9857. Remote exploitation of the attack is possible. No exploit is available.