Cross-site Scripting Vulnerability in Frank Koenen Web Plugin
CVE-2025-22548
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 January 2025
What is CVE-2025-22548?
A Cross-site Scripting (XSS) vulnerability exists in the Frank Koenen ldap_login_password_and_role_manager plugin, allowing malicious actors to inject arbitrary scripts into web pages viewed by users. This flaw can enable an attacker to execute scripts in the context of a victim’s session, potentially leading to unauthorized actions or data exposure. The vulnerability affects all versions up to 1.0.12, posing a significant risk to websites utilizing this plugin.
Affected Version(s)
ldap_login_password_and_role_manager <= 1.0.12