CVE-2025-23828
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 16, 2025
CWE ID 79
Summary
CVE-2025-23828 is a Cross-Site Scripting (XSS) vulnerability affecting the WordPress Data Guard plugin from an unknown version up to 8. An attacker can exploit this issue by injecting malicious scripts into a webpage generated by the plugin, which can be stored and executed on subsequent visits. This can lead to unauthorized data access or theft of user sessions, potentially allowing attackers to gain control of affected user accounts. WordPress users running the Data Guard plugin are advised to update to a patched version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.