CVE-2025-23662

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23662 is a newly disclosed vulnerability that combines Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) attacks. Affecting WP Panoramio from versions n/a through 1.5.0, an attacker can exploit the CSRF weakness to execute arbitrary actions on behalf of a targeted user. Subsequently, the Stored XSS component enables the attacker to inject malicious scripts into the targeted user's web session, potentially leading to serious data breaches or account takeovers. Users are strongly advised to update WP Panoramio to the latest version as soon as possible to mitigate the risk of these attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share