CVE-2025-31844
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 1, 2025
CWE ID 79
Summary
CVE-2025-31844 is a Cross-Site Scripting (XSS) vulnerability affecting Magical Blocks, a plugin used in WordPress websites. The issue, which was present from an unknown version up to 1.0.10, allows an attacker to inject malicious scripts into a webpage, potentially stealing user data or taking control of user sessions. This vulnerability arises due to improper neutralization of user inputs during web page generation. It is important for users to update their Magical Blocks plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.