CVE-2025-31837

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Apr 1, 2025
CWE ID 79

Summary

CVE-2025-31837 is a Cross-site Scripting (XSS) vulnerability affecting WP Proposals, a plugin used for creating and managing proposals in WordPress. The flaw, specifically an Improper Neutralization of Input During Web Page Generation issue, allows an attacker to inject malicious scripts into a targeted website. This stored XSS vulnerability can be exploited to steal user data, launch phishing attacks, or perform other malicious actions. WP Proposals versions from n/a through 2.3 are susceptible to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share