CVE-2025-31096
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 28, 2025
CWE ID 79
Summary
CVE-2025-31096 is a Cross-Site Scripting (XSS) vulnerability affecting the WPXPO PostX plugin. The flaw, which is DOM-Based, occurs during web page generation in PostX versions from n/a to 4.1.25. An attacker can exploit this vulnerability to inject malicious scripts into a victim's web page, potentially stealing sensitive information or taking control of the user's session. This issue can lead to security risks and privacy concerns, emphasizing the importance of applying the necessary patches or updates to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PostX Plugin
Affected Vendors
- WordPress