CVE-2025-27346
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-27346 is a Cross-SiteScripting (XSS) vulnerability affecting the gerrygooner Rebuild Permalinks plugin. The flaw, situated in the web page generation process, enables an attacker to inject malicious scripts into a targeted user's browser. The issue can potentially be exploited to steal sensitive information, or even take control of the user's account. This security weakness impacts gerrygooner Rebuild Permalinks versions from n/a through 1.6. To mitigate this risk, users are advised to update their plugin to the latest available version or consider disabling the plugin until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.