CVE-2025-27351
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 24, 2025
CWE ID 79
Summary
CVE-2025-27351 is a Cross-site Scripting (XSS) vulnerability affecting the Local Search SEO Contact Page, version n/a through 4.0.1. An attacker can exploit this Improper Neutralization of Input issue during web page generation to inject and execute malicious scripts in users' browsers. The result is potential theft of sensitive data or unauthorized access to user accounts. Users are strongly advised to update to a patched version of the Local Search SEO Contact Page to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- WordPress