The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks
History

Fri, 09 May 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Geminilabs
Geminilabs site Reviews
Weaknesses CWE-79
CPEs cpe:2.3:a:geminilabs:site_reviews:*:*:*:*:*:wordpress:*:*
Vendors & Products Geminilabs
Geminilabs site Reviews

Wed, 19 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Mar 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks
Title Site Reviews < 7.2.5 - Unauthenticated Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-03-19T06:00:02.199Z

Updated: 2025-03-19T14:36:35.550Z

Reserved: 2025-02-11T14:10:57.503Z

Link: CVE-2025-1232

cve-icon Vulnrichment

Updated: 2025-03-19T14:36:04.652Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-19T06:15:15.940

Modified: 2025-05-09T12:00:30.697

Link: CVE-2025-1232

cve-icon Redhat

No data.