CVE-2025-1487

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 13, 2025
Updated: Mar 14, 2025

Summary

CVE-2025-1487 is a vulnerability affecting the WoWPth WordPress plugin before version 2.0. This issue arises due to the plugin's failure to properly sanitize and escape a user input parameter. As a result, an attacker can inject malicious scripts, leading to a Reflected Cross-Site Scripting (XSS) attack. This vulnerability poses a significant risk to high privilege users, including admins, who may be targeted to gain unauthorized access to sensitive information or perform unintended actions on the affected WordPress site.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share