Cross-site Scripting Vulnerability in Levan Tarbor Forex Calculators
CVE-2025-22689

6.5MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
16 February 2025

Summary

A Cross-site Scripting (XSS) vulnerability has been identified in Levan Tarbor Forex Calculators. This flaw allows attackers to inject malicious scripts into web pages that can be executed in the user's browser, leading to unauthorized actions and potential data breaches. The issue affects versions up to 1.3.6. It is crucial for users to update their installations to mitigate risks associated with this vulnerability and ensure the safety of their web applications.

Affected Version(s)

Forex Calculators <= 1.3.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.