CVE-2025-3661
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Apr 19, 2025
Updated: Apr 21, 2025
CWE ID 79
Summary
CVE-2025-3661 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the SB Chart block plugin for WordPress. Versions up to and including 1.2.6 are susceptible to this issue. Attackers, who must have Contributor-level access or higher, can exploit this vulnerability by injecting malicious scripts into the 'className' parameter. These scripts will then be stored and executed whenever a user accesses the affected page. This poses a significant security risk, as it allows attackers to gain unauthorized control over a user's web session.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.