CVE-2025-25074

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 7, 2025
CWE ID 352

Summary

CVE-2025-25074 is a newly discovered vulnerability affecting WP Social Stream, a WordPress plugin. The issue involves a Cross-Site Request Forgery (CSRF) vulnerability that also includes Stored XSS (Cross-Site Scripting) capabilities. This means an attacker can manipulate user sessions and inject malicious scripts into web pages viewed by other users. The vulnerability is present in versions of WP Social Stream ranging from n/a to 1.1, making it essential for users to update their plugins as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share