Reflected XSS Vulnerability in TaxoPress WordPress Tag Cloud Plugin
CVE-2025-22735
7.1HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 21 January 2025
Summary
The TaxoPress WordPress Tag Cloud Plugin – Tag Groups suffers from a reflected XSS vulnerability due to improper input neutralization during web page generation. This flaw allows attackers to inject malicious scripts, potentially compromising user sessions and enabling unauthorized actions. This vulnerability affects users of the plugin across various versions up to 2.0.4, posing a significant risk to the security of websites utilizing the plugin.
Affected Version(s)
WordPress Tag Cloud Plugin – Tag Groups <= 2.0.4
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
minhtuanact (Patchstack Alliance)