CVE-2025-8722

Content Views <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Grid and List Widgets

The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widgets in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 16,221 live websites that are affected by CVE-2025-8722.

Run a Free Instant Scan




Affected Software

Product  Content Views
Category Wordpress Plugins
Vulnerable Domains16,221 live websites (38% of Content Views install base)
Vulnerable Versions
  • from 0 through 4.1
Vulnerable Versions Count79 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Sep 6, 2025
  • Updated - Sep 8, 2025

Credits

  • Craig Smith (finder)

Website Distribution by Country

Number of websites using CVE-2025-8722
United States3,859 websites



Netherlands2,574 websites
Germany1,310 websites
Russia1,062 websites
Italy608 websites
France602 websites
Japan577 websites
GB486 websites
Belgium426 websites
Spain368 websites

Website Distribution by TLD

Number of websites using CVE-2025-8722
.com5,251 websites
.nl2,499 websites
.org944 websites
.ru897 websites
.de800 websites
.it419 websites
.be405 websites
.net399 websites
.co.uk249 websites
.es222 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-8722

Top websites that are affected by CVE-2025-8722. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.es Spain*,***
********.com United States**,***
******.com United States**,***
*******.com United States**,***
****.***.org United States**,***
*****.app Bulgaria**,***
*******.com United States**,***
*********.com United States**,***
************.it United States**,***
*********************.com United States**,***
See full domain list

FAQ

CVE-2025-8722 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Content Views
A total of 16,221 websites have been identified as vulnerable to CVE-2025-8722, based on global website indexing conducted by WebTechSurvey.
The Content Views is affected by the CVE-2025-8722 vulnerability.
Content Views versions up to and including 4.1 are vulnerable to CVE-2025-8722.