CVE-2025-28905
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Chaser324 Featured Posts Grid allows Stored XSS. This issue affects Featured Posts Grid: from n/a through 1.7.
More information : https://patchstack.com/database/wordpress/plugin/featured-posts-grid/vulnerability/wordpress-featured-posts-grid-plugin-1-7-csrf-to-stored-xss-vulnerability?_s_id=cve
