Cross-Site Scripting Vulnerability in AddFunc Mobile Detect Plugin by AddFunc
CVE-2025-22550
6.5MEDIUM
Summary
The AddFunc Mobile Detect plugin is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. This flaw arises due to improper handling of user input during web page generation, leading to persistent XSS attacks. Webmasters using affected versions are strongly advised to take immediate action to mitigate potential security risks associated with unauthorized script execution.
Affected Version(s)
AddFunc Mobile Detect <= 3.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SOPROBRO (Patchstack Alliance)