CVE-2025-22706
Published: 21 January 2025
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.mihai Social Pug: Author Box allows Reflected XSS. This issue affects Social Pug: Author Box: from n/a through 1.0.0.
Security Summary
CVE-2025-22706 is an Improper Neutralization of Input During Web Page Generation vulnerability, classified as Reflected Cross-site Scripting (XSS) under CWE-79, in the Social Pug: Author Box WordPress plugin by iova.mihai. This issue affects all versions of the plugin from n/a through 1.0.0 and was published on 2025-01-21.
The vulnerability carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating it is exploitable over the network with low attack complexity, no required privileges, but user interaction is necessary. Remote attackers can trick authenticated or unauthenticated users into interacting with malicious content, such as a crafted link, to inject and execute arbitrary scripts in the victim's browser context with changed scope, potentially leading to low-level impacts on confidentiality, integrity, and availability.
The Patchstack advisory at https://patchstack.com/database/wordpress/plugin/social-pug-author-box/vulnerability/wordpress-social-pug-author-box-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve provides details on this Reflected XSS vulnerability in Social Pug: Author Box version 1.0.0, including recommended mitigations for affected WordPress installations.
Details
- CWE(s)