CVE-2025-23500
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 22, 2025
CWE ID 79
Summary
CVE-2025-23500 is a Cross-site Scripting (XSS) vulnerability affecting the Simple Custom post type custom field plugin before version 1.0.3. An attacker can exploit this flaw by injecting malicious scripts into a webpage generated by the plugin, potentially stealing user data or taking control of user sessions. The issue occurs due to improper neutralization of user-supplied input, making it essential for users to upgrade to a patched version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.