CVE-2025-2700
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-2700 is a newly disclosed vulnerability affecting michelson Dante Editor versions up to 0.4.4. The issue lies within the Insert Link Handler component, which is reportedly problematic. An attacker can exploit this vulnerability through cross-site scripting, allowing them to inject malicious code into a victim's webpage. The attack can be initiated remotely, making it a significant threat. Sadly, the exploit has been made public, increasing the risk for potential attacks. Despite early disclosure to the vendor, they have not provided any response or patch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- My Auctions Allegro Plugin
Affected Vendors
- WordPress