A vulnerability identified as problematic has been detected in Unify Plugin up to 3.4.7 on WordPress. Affected is the function
unify_checkout
of the component Shortcode Handler. Performing manipulation results in cross site scripting.
This vulnerability was named CVE-2025-9130. The attack may be initiated remotely. There is no available exploit.