CVE-2025-0368
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-0368 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Banner Garden Plugin for WordPress. The plugin, up to version 0.1.3, fails to sanitize and escape user input before rendering it on the page. This issue paves the way for malicious scripts to be executed in the context of the website, posing a threat to both high privilege users like administrators and unauthenticated visitors. An attacker exploiting this vulnerability could steal sensitive data or take control of the affected WordPress site. Users are urged to update the plugin to a secure version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.