CVE-2025-23795

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 16, 2025
CWE ID 79

Summary

CVE-2025-23795 is a Cross-site Scripting (XSS) vulnerability affecting Gold Plugins Easy FAQs. The flaw, which allows stored XSS attacks, resides in the plugin's web page generation process. An attacker can inject malicious scripts into the affected plugin, exploiting the vulnerability to execute arbitrary code in users' browsers. This issue poses a significant risk, as it can lead to data theft, unauthorized access, and other malicious activities. Easy FAQs versions from n/a through 3.2.1 are reportedly impacted. Users are strongly encouraged to update the plugin to its latest, secure version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share