CVE-2025-13355

URL Shortify < 1.11.4 - Reflected XSS

The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.


We have discovered 1,538 live websites that are affected by CVE-2025-13355.

Run a Free Instant Scan




Affected Software

Product  Url Shortify
Category Wordpress Plugins
Vulnerable Domains1,538 live websites (34% of Url Shortify install base)
Vulnerable Versions
  • from 0 through 1.11.4
Vulnerable Versions Count64 versions ( 83% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 15, 2025
  • Updated - Dec 15, 2025

Credits

  • Gregory Allegoet (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-13355
United States495 websites



Germany200 websites
GB73 websites
Iran65 websites
France65 websites
Italy42 websites
Russia42 websites
Poland37 websites
Spain35 websites
Canada32 websites

Website Distribution by TLD

Number of websites using CVE-2025-13355
.com608 websites
.org124 websites
.de109 websites
.net47 websites
.it33 websites
.ru30 websites
.co.uk29 websites
.pl28 websites
.com.br25 websites
.fr22 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-13355

Top websites that are affected by CVE-2025-13355. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.org United States**,***
***************.de Germany**,***
*********.net United States**,***
****.org United States**,***
********************.com Bulgaria**,***
****.org GB***,***
******.com Germany***,***
***.***.ua Ukraine***,***
****************.com United States***,***
*******.ir Iran***,***
See full domain list

FAQ

CVE-2025-13355 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Url Shortify
A total of 1,538 websites have been identified as vulnerable to CVE-2025-13355, based on global website indexing conducted by WebTechSurvey.
The Url Shortify is affected by the CVE-2025-13355 vulnerability.
Url Shortify versions up to 1.11.4 are vulnerable to CVE-2025-13355.
CVE-2025-13355 is resolved in version 1.11.4 of Url Shortify.