CVE-2025-22549

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 7, 2025
CWE ID 79

Summary

CVE-2025-22549 is a Cross-site Scripting (XSS) vulnerability affecting WP Github, a WordPress plugin. The issue allows an attacker to inject malicious scripts into a website, which can be stored and executed on demand. This vulnerability, present in versions from n/a to 1.3.3, can lead to unintended execution of malicious code on unsuspecting users visiting the affected website. Successful exploitation can result in data theft, session hijacking, or other forms of cyberattacks. Users are strongly urged to update their WP Github plugin as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share