CVE-2025-31463

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Mar 28, 2025
CWE ID 79

Summary

CVE-2025-31463 is a Cross-site Scripting (XSS) vulnerability affecting the TGG WP Optimizer plugin. The flaw, which allows Stored XSS attacks, resides in the plugin's handling of user-supplied input during web page generation. Successful exploitation of this vulnerability could result in the injection of malicious scripts into a victim's web page, potentially leading to unauthorized access or data theft. The issue has been reported to affect TGG WP Optimizer versions from n/a through 1.22. It is essential for users to update their plugin to the latest version or consider disabling it as a temporary measure until a patch is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share