CVE-2025-3189
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-3189 is a stored Cross-Site Scripting (XSS) vulnerability affecting DoWISP, a software product, in versions prior to 1.16.2.50. This issue allows an attacker to inject malicious Javascript code into a user's profile picture in SVG format. Upon viewing the affected profile, the malicious script is executed, potentially leading to unauthorized access to user data or even full account takeover. The vulnerability is significant as it bypasses client-side XSS protection and can impact all users who view the affected profile. It is recommended that users update to the latest version of DoWISP as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress