The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks
History

Wed, 19 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Mar 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks
Title Site Reviews < 7.2.5 - Unauthenticated Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-03-19T06:00:02.199Z

Updated: 2025-03-19T14:36:35.550Z

Reserved: 2025-02-11T14:10:57.503Z

Link: CVE-2025-1232

cve-icon Vulnrichment

Updated: 2025-03-19T14:36:04.652Z

cve-icon NVD

Status : Received

Published: 2025-03-19T06:15:15.940

Modified: 2025-03-19T15:15:53.263

Link: CVE-2025-1232

cve-icon Redhat

No data.