CVE-2025-32490

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 79

Summary

CVE-2025-32490 is a Cross-site Scripting (XSS) vulnerability affecting the WebsiteDefender wp secure plugin from versions n/a through 1.2. The issue stems from an improper neutralization of user input during web page generation. attackers can inject malicious scripts into the targeted website, which gets stored and executed on demand whenever the affected webpage is loaded. This puts users of the affected website at risk of having their browsing sessions hijacked, sensitive data stolen, or their systems compromised. To mitigate the risk, users are advised to update the WebsiteDefender plugin to the latest version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share