CVE-2025-23795
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-23795 is a Cross-site Scripting (XSS) vulnerability affecting Gold Plugins Easy FAQs. The flaw, which allows stored XSS attacks, resides in the plugin's web page generation process. An attacker can inject malicious scripts into the affected plugin, exploiting the vulnerability to execute arbitrary code in users' browsers. This issue poses a significant risk, as it can lead to data theft, unauthorized access, and other malicious activities. Easy FAQs versions from n/a through 3.2.1 are reportedly impacted. Users are strongly encouraged to update the plugin to its latest, secure version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.