CVE-2025-22735

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 21, 2025
CWE ID 79

Summary

CVE-2025-22735 is a Cross-Site Scripting (XSS) vulnerability affecting the WordPress Tag Cloud Plugin – Tag Groups, specifically versions from n/a to 2.0.4. An attacker can exploit this issue by injecting malicious scripts during web page generation in the plugin's tag cloud feature, potentially gaining unauthorized access to user sessions or stealing sensitive information. The flaw arises from improper neutralization of user-supplied input, making it essential for users to update to the latest plugin version or consider alternative solutions to secure their WordPress installations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share