CVE-2025-23624
Published: 23 January 2025
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alessandro Benoit WpDevTool wpdevtool allows Reflected XSS.This issue affects WpDevTool: from n/a through <= 0.1.1.
Security Summary
CVE-2025-23624 is an Improper Neutralization of Input During Web Page Generation vulnerability, classified as Reflected Cross-site Scripting (XSS) under CWE-79, in the WpDevTool WordPress plugin developed by Alessandro Benoit. This issue affects WpDevTool versions from n/a through 0.1.1 inclusive. The vulnerability was published on 2025-01-23 and carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
Remote attackers can exploit this vulnerability over the network with low attack complexity and no privileges required, though it requires user interaction such as visiting a maliciously crafted link. Exploitation enables reflected XSS, allowing attackers to inject and execute arbitrary scripts in the context of a victim's browser, with changed scope leading to low impacts on confidentiality, integrity, and availability.
The Patchstack advisory documents this Reflected XSS vulnerability in the WordPress WpDevTool plugin version 0.1.1.
Details
- CWE(s)