CVE-2025-15363: Unknown Get Use Apis

Medium severity, CVSS 5.9. EPSS: 0.1% chance of exploitation in the next 30 days.

The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks under certain server configurations.

Affected products

  • Unknown Get Use Apis: before 2.0.10 (fixed in 2.0.10)

Published 2026-03-18. Last modified 2026-06-17.