CVE-2025-1773
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-1773 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Traveler theme for WordPress. This issue, present in all versions up to 3.1.8, arises due to insufficient input sanitization and output escaping. Attackers can exploit this weakness by injecting malicious scripts into multiple parameters. Successful exploitation allows unauthenticated adversaries to execute arbitrary code on affected pages, potentially putting user data at risk. Users are strongly urged to update their Traveler theme to the latest version, or consider alternative themes, to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.