CVE-2025-31463
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2025-31463 is a Cross-site Scripting (XSS) vulnerability affecting the TGG WP Optimizer plugin. The flaw, which allows Stored XSS attacks, resides in the plugin's handling of user-supplied input during web page generation. Successful exploitation of this vulnerability could result in the injection of malicious scripts into a victim's web page, potentially leading to unauthorized access or data theft. The issue has been reported to affect TGG WP Optimizer versions from n/a through 1.22. It is essential for users to update their plugin to the latest version or consider disabling it as a temporary measure until a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.