CVE-2025-0368

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 4, 2025

Summary

CVE-2025-0368 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Banner Garden Plugin for WordPress. The plugin, up to version 0.1.3, fails to sanitize and escape user input before rendering it on the page. This issue paves the way for malicious scripts to be executed in the context of the website, posing a threat to both high privilege users like administrators and unauthenticated visitors. An attacker exploiting this vulnerability could steal sensitive data or take control of the affected WordPress site. Users are urged to update the plugin to a secure version as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share