CVE-2025-31096

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 28, 2025
CWE ID 79

Summary

CVE-2025-31096 is a Cross-Site Scripting (XSS) vulnerability affecting the WPXPO PostX plugin. The flaw, which is DOM-Based, occurs during web page generation in PostX versions from n/a to 4.1.25. An attacker can exploit this vulnerability to inject malicious scripts into a victim's web page, potentially stealing sensitive information or taking control of the user's session. This issue can lead to security risks and privacy concerns, emphasizing the importance of applying the necessary patches or updates to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share