CVE-2025-31897
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 1, 2025
CWE ID 79
Summary
CVE-2025-31897 is a Cross-site Scripting (XSS) vulnerability affecting Arrow Custom Feed for Twitter, version n/a through 1.5.3. Maliciously crafted input during web page generation can be stored and executed in users' web browsers, leading to potential data theft or unauthorized access. This issue arises due to insufficient input validation in the Arrow Custom Feed for Twitter plugin. The vulnerability can result in code injection and security breaches for affected users. Upgrading to a secure version of this plugin is strongly advised to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.