CVE-2025-23614
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Feb 3, 2025
CWE ID 79
Summary
CVE-2025-23614 is a Cross-Site Scripting (XSS) vulnerability affecting WordPress Additional Logins. The flaw, which allowsReflected XSS attacks, exists due to improper neutralization of user input during web page generation. This issue can be exploited by attackers to inject malicious scripts into a victim's web browser, potentially stealing sensitive information or taking control of the user's account. WordPress Additional Logins versions from n/a through 1.0.0 are affected, making it essential for users to update to a secure version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share