Reflected XSS Vulnerability in Convoy Media Category Library by WordPress
CVE-2025-22344
7.1HIGH
What is CVE-2025-22344?
The Convoy Media Category Library for WordPress, versions n/a through 2.7, is vulnerable to reflected cross-site scripting (XSS). This vulnerability allows attackers to inject malicious scripts into web pages, which can be executed in the context of the user's browser. If exploited, this could lead to unauthorized access to sensitive user data and various types of attacks. It is crucial for users of affected versions to implement the necessary patches to safeguard their applications.
Affected Version(s)
Media Category Library <= 2.7