CVE-2025-23428

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 14, 2025
CWE ID 79

Summary

CVE-2025-23428 is a Cross-Site Scripting (XSS) vulnerability affecting the QMean – WordPress Did You Mean plugin. The issue stems from improper neutralization of user input during web page generation. Unauthorized users can inject malicious scripts into the plugin, which may result in stolen information or unauthorized actions on affected websites. Websites utilizing QMean – WordPress Did You Mean version 2.0 and below are vulnerable to this Reflected XSS vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share