CVE-2025-9427: Lemonsoft WordPress Add-On

High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lemonsoft WordPress add on allows Cross-Site Scripting (XSS).This issue affects WordPress add on: 2025.7.1.

Affected products

  • Lemonsoft WordPress Add-On: version 2025.7.1 only

Published 2026-01-13. Last modified 2026-06-17.