CVE-2025-14118 | Starred Review Plugin up to 1.4.2 on WordPress $_SERVER['PHP_SELF'] cross site scripting
A vulnerability identified as problematic has been detected in Starred Review Plugin up to 1.4.2 on WordPress. Impacted is an unknown function. This manipulation of the argument $_SERVER['PHP_SELF'] causes cross site scripting.
This vulnerability is tracked as CVE-2025-14118. The attack is possible to be carried out remotely. No exploit exists.