CVE-2025-28933
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-28933 is a newly disclosed vulnerability that impacts MaxA/B from an unknown version up to 2.2.2. This issue combines two serious threats: a Cross-Site Request Forgery (CSRF) vulnerability and Stored Cross-Site Scripting (XSS). An attacker can exploit the CSRF vulnerability to perform unintended actions on behalf of a victim in the MaxA/B application. Additionally, they can take advantage of the Stored XSS to inject malicious scripts into the application, which can be executed whenever the vulnerable page is loaded. The combination of these vulnerabilities poses a significant risk to users of the affected MaxA/B versions. It is recommended that users upgrade to a patched version as soon as possible to mitigate these threats.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress