CVE-2025-2700

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 24, 2025
Updated: Apr 1, 2025
CWE ID 352

Summary

CVE-2025-2700 is a newly disclosed vulnerability affecting michelson Dante Editor versions up to 0.4.4. The issue lies within the Insert Link Handler component, which is reportedly problematic. An attacker can exploit this vulnerability through cross-site scripting, allowing them to inject malicious code into a victim's webpage. The attack can be initiated remotely, making it a significant threat. Sadly, the exploit has been made public, increasing the risk for potential attacks. Despite early disclosure to the vendor, they have not provided any response or patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • My Auctions Allegro Plugin

Affected Vendors

  • WordPress