CVE-2025-22584
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-22584 is a Cross-site Scripting (XSS) vulnerability affecting Timeline Pro, a plugin used for generating timelines on websites. The flaw, specifically an improper neutralization of user input during web page generation, permits attackers to inject malicious scripts into a victim's browser while viewing a contaminated page. This issue puts users at risk of data theft, session hijacking, and other malicious activities. The vulnerability spans from an unspecified version n/a up to 1.3. It is crucial that users update their Timeline Pro plugin to the latest, secured version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.