Cyber Posture

CVE-2025-22706

High

Published: 21 January 2025

Published
21 January 2025
Modified
28 April 2026
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0013 32.1th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.mihai Social Pug: Author Box allows Reflected XSS. This issue affects Social Pug: Author Box: from n/a through 1.0.0.

Security Summary

CVE-2025-22706 is an Improper Neutralization of Input During Web Page Generation vulnerability, classified as Reflected Cross-site Scripting (XSS) under CWE-79, in the Social Pug: Author Box WordPress plugin by iova.mihai. This issue affects all versions of the plugin from n/a through 1.0.0 and was published on 2025-01-21.

The vulnerability carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating it is exploitable over the network with low attack complexity, no required privileges, but user interaction is necessary. Remote attackers can trick authenticated or unauthenticated users into interacting with malicious content, such as a crafted link, to inject and execute arbitrary scripts in the victim's browser context with changed scope, potentially leading to low-level impacts on confidentiality, integrity, and availability.

The Patchstack advisory at https://patchstack.com/database/wordpress/plugin/social-pug-author-box/vulnerability/wordpress-social-pug-author-box-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve provides details on this Reflected XSS vulnerability in Social Pug: Author Box version 1.0.0, including recommended mitigations for affected WordPress installations.

Details

CWE(s)
CWE-79

References