CVE-2025-30847
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2025-30847 is a Cross-site Scripting (XSS) vulnerability affecting Ashley Novelist from versions n/a through 1.2.3. An attacker can inject malicious code into a web page generated by Ashley Novelist, which is then executed in a user's browser when they view the affected page. This can lead to unauthorized access to sensitive information or the ability to carry out actions on behalf of the user. The vulnerability arises due to improper neutralization of user input. Stored XSS attacks can persist even after the initial attack vector is removed, posing a significant risk to users until the vulnerability is patched.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress