CVE-2025-39455
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-39455 is a newly discovered vulnerability affecting IP2Location Variables, version n/a through 2.9.5. This issue combines a Cross-Site Request Forgery (CSRF) weakness with the potential for Reflected XSS (Cross-Site Scripting). An attacker, who successfully exploits this vulnerability, can inject malicious scripts into a victim's web browser, potentially leading to data theft or system compromise. The CSRF flaw enables an attacker to forge requests, appearing to originate from the victim, while the Reflected XSS component allows the execution of harmful scripts once the request is processed. Users are advised to update to the latest IP2Location Variables version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress