CVE-2025-28929
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 11, 2025
CWE ID 79
Summary
CVE-2025-28929 is a Cross-site Scripting (XSS) vulnerability affecting the Tabbed Login Widget, version 1.1.2 and earlier. The flaw, called Stored XSS, is due to improper neutralization of user input during web page generation. Cybercriminals can exploit this vulnerability to inject malicious scripts into a website, potentially stealing user data or taking control of their accounts when they visit the compromised site. This issue poses a significant risk and requires immediate remediation to prevent potential data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress