CVE-2025-23669
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-23669 is a Cross-site Scripting (XSS) vulnerability affecting the WP Smart Tooltip plugin for WordPress. The issue, named "Improper Neutralization of Input During Web Page Generation," allows attackers to inject malicious scripts into a website, potentially stealing user data or taking control of their sessions. The vulnerability exists in all versions of WP Smart Tooltip from n/a through 1.0.0, posing a significant threat to websites using this plugin. To mitigate the risk, WordPress users should update their plugin to the latest version or consider disabling it until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.