CVE-2025-26574
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-26574 is a Cross-site Scripting (XSS) vulnerability affecting the Google Drive WP Media plugin. The issue stems from improper neutralization of user input during web page generation. An attacker can exploit this flaw to inject malicious scripts into a victim's web page, potentially stealing sensitive data or taking control of their account. The vulnerability has been identified in versions of Google Drive WP Media from n/a through 2.4.4. Users are strongly advised to update their plugins to the latest version or consider alternative solutions to secure their websites.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress