CVE-2025-32117

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 8, 2025
CWE ID 79

Summary

CVE-2025-32117 is a Cross-site Scripting (XSS) vulnerability affecting OTWthemes Widgetize Pages Light. This issue stems from improper neutralization of user input during web page generation. Maliciously crafted scripts can be reflected in the affected pages and injected into unsuspecting users' browsers, potentially leading to data theft, unauthorized access, or other malicious activities. The vulnerability affects all versions of Widgetize Pages Light from n/a to 3.0. It is crucial that users of this plugin update to a secure version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share