Junglewise Threat Intelligence

CVE-2025-69140: SeventhQueen SweetDate Core unauthenticated XSS

CVE-2025-69140 · Severity: high · CVSS 7.1 · Published 2026-06-17

Executive brief

SweetDate Core, a WordPress plugin used for community and dating site functionality, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a site visitor or administrator into clicking a specially crafted link, an attacker could steal session information, redirect users to malicious websites, or deface site content. This can lead to unauthorized access to user accounts and damage to the website's reputation.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the SweetDate Core plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim to interact with a malicious link or visit a crafted page. Successful exploitation can lead to the execution of scripts in the context of the victim's browser session, potentially allowing for session hijacking or unauthorized actions. The issue is resolved in version 1.1.5.

Affected products

  • SeventhQueen SweetDate Core < 1.1.5

Timeline

  • 2025-10-30: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-05-26: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD

References