CVE-2025-12684

URL Shortify < 1.11.3 - Reflected XSS

The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in the page, leading to a reflected cross site scripting, which could be used against high-privilege users such as admins.


We have discovered 1,535 live websites that are affected by CVE-2025-12684.

Run a Free Instant Scan




Affected Software

Product  Url Shortify
Category Wordpress Plugins
Vulnerable Domains1,535 live websites (33% of Url Shortify install base)
Vulnerable Versions
  • from 0 through 1.11.3
Vulnerable Versions Count63 versions ( 82% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 15, 2025
  • Updated - Dec 15, 2025

Credits

  • Nguyễn Đức Toàn (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-12684
United States494 websites



Germany200 websites
GB73 websites
Iran65 websites
France65 websites
Italy42 websites
Russia42 websites
Poland37 websites
Spain35 websites
Canada32 websites

Website Distribution by TLD

Number of websites using CVE-2025-12684
.com608 websites
.org124 websites
.de109 websites
.net46 websites
.it33 websites
.ru30 websites
.co.uk29 websites
.pl28 websites
.com.br25 websites
.fr22 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-12684

Top websites that are affected by CVE-2025-12684. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.org United States**,***
***************.de Germany**,***
*********.net United States**,***
****.org United States**,***
********************.com Bulgaria**,***
****.org GB***,***
******.com Germany***,***
***.***.ua Ukraine***,***
****************.com United States***,***
*******.ir Iran***,***
See full domain list

FAQ

CVE-2025-12684 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Url Shortify
A total of 1,535 websites have been identified as vulnerable to CVE-2025-12684, based on global website indexing conducted by WebTechSurvey.
The Url Shortify is affected by the CVE-2025-12684 vulnerability.
Url Shortify versions up to 1.11.3 are vulnerable to CVE-2025-12684.
CVE-2025-12684 is resolved in version 1.11.3 of Url Shortify.