CVE-2025-0721

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 27, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-0721 is a newly disclosed vulnerability affecting the image_gallery function in the needyamin plugin version 1.0. The issue lies in the file /view.php, where a cross-site scripting (XSS) vulnerability is present. This weakness can be triggered by manipulating the argument username. An attacker can initiate the attack remotely, making it a serious concern. Unfortunately, the vendor has not responded to the disclosure, leaving users at risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share