Stored Cross-Site Scripting Vulnerability in AppPresser Plugin for WordPress
CVE-2025-1561
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 March 2025
What is CVE-2025-1561?
The AppPresser – Mobile App Framework plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to insufficient sanitization of the 'title' parameter. This vulnerability exists in all versions up to and including 4.4.10, allowing unauthenticated attackers to inject malicious web scripts. When logging is enabled, these scripts are executed whenever a user accesses the compromised page, potentially leading to unauthorized actions and data exposure.
Affected Version(s)
AppPresser – Mobile App Framework * <= 4.4.10