CVE-2025-0721
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 27, 2025
CWE ID 94
CWE ID 79
Summary
CVE-2025-0721 is a newly disclosed vulnerability affecting the image_gallery function in the needyamin plugin version 1.0. The issue lies in the file /view.php, where a cross-site scripting (XSS) vulnerability is present. This weakness can be triggered by manipulating the argument username. An attacker can initiate the attack remotely, making it a serious concern. Unfortunately, the vendor has not responded to the disclosure, leaving users at risk of exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Image Gallery