CVE-2025-23621

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 24, 2025
CWE ID 79

Summary

CVE-2025-23621 is a Cross-site Scripting (XSS) vulnerability affecting the Causes – Donation Plugin from version n/a through 1.0.01. An attacker can exploit this issue by injecting malicious scripts into web pages generated by the plugin, which could lead to unintended execution of code in users' browsers. This could potentially result in session hijacking, data theft, or other malicious activities. Users are advised to update the plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share