← WordPress Vulnerabilities
WordPress security by component

Puzzles

Puzzles is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Feb 13, 2025; the highest CVE/CNA score is 8.1.

Theme slug: puzzles

CVE-2025-0837: Puzzles: Cross-site scripting

Puzzles is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedFeb 13, 2025
Safe version guidanceSee mitigation notes
Safe version
Feb 13, 2025 CVE-2025-0837
Puzzles: Cross-site scripting
Puzzles is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 13, 2025 CVE-2024-13770
Puzzles | WP Magazine / Review with Store: Code execution
Puzzles | WP Magazine / Review with Store is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.1
NVD9.8
Feb 12, 2025 CVE-2024-13769
Puzzles | WP Magazine / Review with Store: Cross-site scripting
Puzzles | WP Magazine / Review with Store is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4