CVE-2025-28878
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2025-28878 is a Cross-site Scripting (XSS) vulnerability affecting Will Brubaker's Awesome Surveys. The flaw, labeled as Improper Neutralization of Input During Web Page Generation, enables an attacker to inject malicious scripts into web pages generated by the application. This vulnerability can lead to Stored XSS attacks, putting users at risk of having their browsing sessions hijacked or sensitive information exposed. The issue affected versions of Awesome Surveys ranging from n/a to 2.0.10. It is crucial for users to update their software to the latest version, or take other appropriate measures, to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress