CVE-2025-23560

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23560 is a newly discovered vulnerability affecting the Elke Hinze, Plumeria Web Design Web Testimonials application. The weakness involves a Cross-Site Request Forgery (CSRF) issue, which can lead to Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows malicious actors to inject malicious scripts into a victim's browser, potentially stealing sensitive information or taking control of user sessions. The issue affects versions of Web Testimonials ranging from n/a through 1.2. Users are strongly advised to update their systems as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share