CVE-2025-23775
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-23775 is a Cross-site Scripting (XSS) vulnerability affecting the WWP GMAPS plugin for WPBakery Page Builder Free. The issue enables an attacker to inject malicious scripts into web pages generated by the plugin, potentially stealing user data or taking control of user sessions. This vulnerability can be exploited through stored XSS attacks, allowing attackers to execute scripts even after the user has left the infected page. The affected versions of the plugin range from n/a to 1.2. Users are strongly advised to update to the latest, secure version of the plugin to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.