CVE-2025-26947

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 25, 2025
CWE ID 79

Summary

CVE-2025-26947 is a Cross-site Scripting (XSS) vulnerability affecting the Services Section block of bPlugins. The flaw, located in the web page generation process, allows malicious scripts to be stored and executed in users' browsers. This issue can lead to unauthorized access to user data or hijacking of user sessions. The vulnerability affects versions of the Services Section block from n/a through 1.3.4. Users are advised to update their installations as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share