CVE-2025-23878
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2025-23878 is a Cross-site Scripting (XSS) vulnerability affecting the Post-to-Post Links plugin, version n/a through 4.2. The flaw lies in the improper neutralization of user input during web page generation. An attacker can exploit this vulnerability to inject malicious scripts into a website, posing a threat to unsuspecting users who visit the affected site. Successful exploitation could lead to data theft, session hijacking or other malicious activities. It is recommended that users upgrade to the latest version of the Post-to-Post Links plugin to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.