Cross-Site Scripting Vulnerability in List Pages at Depth by Ben Huson
CVE-2025-22517

6.5MEDIUM

Key Information:

Vendor
Ben Huson
Status
List Pages At Depth
Vendor
CVE Published:
7 January 2025

Summary

A Cross-site Scripting (XSS) vulnerability exists in the List Pages at Depth plugin developed by Ben Huson, which allows for stored XSS attacks. This issue can be exploited due to improper neutralization of input during web page generation. Affected versions include all versions from n/a through 1.5, potentially compromising user data and website integrity.

Affected Version(s)

List Pages at Depth <= 1.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SOPROBRO (Patchstack Alliance)
.