A vulnerability, which was classified as problematic, has been found in Xavins List Subpages Plugin up to 1.3 on WordPress. Affected by this issue is the function xls of the component Shortcode Handler. The manipulation leads to cross site scripting.

This vulnerability is handled as CVE-2025-4220. The attack may be launched remotely. There is no exploit available.