Reflected XSS Vulnerability in TaxoPress WordPress Tag Cloud Plugin
CVE-2025-22735

7.1HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
21 January 2025

Summary

The TaxoPress WordPress Tag Cloud Plugin – Tag Groups suffers from a reflected XSS vulnerability due to improper input neutralization during web page generation. This flaw allows attackers to inject malicious scripts, potentially compromising user sessions and enabling unauthorized actions. This vulnerability affects users of the plugin across various versions up to 2.0.4, posing a significant risk to the security of websites utilizing the plugin.

Affected Version(s)

WordPress Tag Cloud Plugin – Tag Groups <= 2.0.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

minhtuanact (Patchstack Alliance)
.