CVE-2025-31847
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-31847 is a Cross-site Scripting (XSS) vulnerability affecting the themelooks mFolio Lite portfolio theme for WordPress. The issue lies in the improper neutralization of user input during web page generation. An attacker can exploit this weakness to inject malicious scripts into a victim's webpage, gaining unauthorized access to sensitive information or taking control of the user's account. This vulnerability exists in versions of mFolio Lite ranging from n/a to 1.2.2. Users are advised to update their theme to the latest secure version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.