CVE-2025-22308
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 7, 2025
CWE ID 79
Summary
CVE-2025-22308 is a Cross-site Scripting (XSS) vulnerability affecting the inc2734 Smart Custom Fields plugin. The issue permits stored XSS attacks due to improper neutralization of user input during web page generation. This vulnerability can be exploited to inject malicious scripts into a website, potentially leading to unauthorized data access or theft of user information. The affected version range for this plugin is from n/a to 5.0.0. It is strongly advised for users to update their plugin to the latest, secure version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.