CVE-2025-22735
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-22735 is a Cross-Site Scripting (XSS) vulnerability affecting the WordPress Tag Cloud Plugin – Tag Groups, specifically versions from n/a to 2.0.4. An attacker can exploit this issue by injecting malicious scripts during web page generation in the plugin's tag cloud feature, potentially gaining unauthorized access to user sessions or stealing sensitive information. The flaw arises from improper neutralization of user-supplied input, making it essential for users to update to the latest plugin version or consider alternative solutions to secure their WordPress installations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.