CVE-2025-1798

All FrameworksWordPressCWE-OtherCVE-2025-1798

CVE-2025-1798

State: PUBLISHED · Published: 2025-03-25 · Updated: 2025-03-25 · Assigner: WPScan
Description
The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/1xxx/CVE-2025-1798.json