CVE-2025-23739
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-23739 is a Cross-site Scripting (XSS) vulnerability affecting WP Ultimate Reviews FREE. This issue, which allows Reflected XSS, stems from improper neutralization of user input during web page generation. Attackers can exploit this flaw to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking or data theft. The vulnerability impacts WP Ultimate Reviews FREE versions from n/a to 1.0.2. It is crucial for users to update their software promptly and practice safe browsing habits to mitigate the risk of such attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.