CVE-2025-6537: Namasha By Mdesign <= 1.2.00 - Authenticated (Contributor+) Stored Cross-Site Scripting via playicon_title Parameter
The Namasha By Mdesign plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘playicon_title’ parameter in all versions up to, and including, 1.2.00 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Security readout for executives and security teams
Plain-English summary
WordPress sites using Namasha By Mdesign through version 1.2.00 could let a Contributor or higher-privileged account place persistent script content into a page. The script can run when that page is viewed, potentially affecting visitors or administrators and enabling limited data exposure or unauthorized page changes.
Executive priority
Prioritize remediation on public sites with multiple contributors, weak account controls, or administrator traffic to contributor-authored pages. Treat it as a prompt patching and access-review item, not an emergency, unless suspicious content or account compromise is found.
Technical view
CVE-2025-6537 is stored cross-site scripting in the plugin's playicon_title parameter, caused by insufficient input sanitization and output escaping. Exploitation requires an authenticated account with Contributor privileges or higher. The CVSS 3.1 score is 6.4, with low confidentiality and integrity impact, no availability impact, and scope change.
Likely exposure
Exposure is limited to WordPress installations running Namasha By Mdesign version 1.2.00 or earlier, particularly where Contributor-level accounts exist or may be compromised. Sites without the plugin, or outside the stated affected versions, are not established as vulnerable by the supplied evidence.
Exploitation context
The attacker must authenticate with Contributor privileges or higher and inject persistent script content through the vulnerable parameter. It then executes when an injected page is accessed. The source bundle marks this CVE as absent from KEV and provides no cited evidence of active exploitation.
Researcher notes
The supplied evidence identifies CWE-79 and versions through 1.2.00 as affected. References include source views for 1.2.00 and 1.2.05, but the bundle does not explicitly identify the fixed version or describe the code change. Confirm remediation status through official guidance and code review rather than assuming 1.2.05 is fixed.
Mitigation direction
Inventory Namasha By Mdesign installations and identify versions 1.2.00 or earlier.
Check official plugin and vendor guidance for a confirmed fixed release before updating.
Until remediation, disable the plugin where operationally acceptable.
Restrict Contributor-level access and remove unnecessary or untrusted accounts.
Review affected pages and remove unauthorized or suspicious stored content.
Validation and detection
Confirm the installed plugin version on every WordPress instance.
Review Contributor and higher-privileged accounts for unexpected access or recent changes.
Inspect content using playicon_title for unexpected script-like or malformed values.
After remediation, verify authorized staging tests cannot persist executable content through the affected field.
Review relevant WordPress and security logs for suspicious content modifications.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.