CVE-2025-0627

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Apr 28, 2025
Updated: Apr 30, 2025
CWE ID 79

Summary

CVE-2025-0627 is a vulnerability affecting the WordPress Tag, Category, and Taxonomy Manager plugin. This issue allows high privilege users, including admins, to execute Stored Cross-Site Scripting attacks. Despite the disallowance of the unfiltered_html capability, especially in multisite setups, the plugin fails to sanitize and escape some widget settings. This security flaw poses a significant risk to WordPress websites using the affected plugin version before 3.30.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share