CVE-2025-2613
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Summary
CVE-2025-2613 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Login Manager plugin for WordPress, versions up to and including 2.0.5. This flaw permits authenticated attackers with administrator-level access to inject malicious scripts into custom logo and background URLs. The injected scripts will execute whenever a user accesses an affected page, putting multi-site installations and those with unfiltered_html disabled at risk. Attackers can leverage this weakness to steal sensitive data or gain further control over the targeted WordPress site.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.