Cross-site Scripting Vulnerability in WP Desk Flexible PDF Coupons
CVE-2025-22825

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 January 2025

What is CVE-2025-22825?

The vulnerability involves the improper neutralization of input during the web page generation process, allowing for stored Cross-site Scripting (XSS) attacks in the WP Desk Flexible PDF Coupons plugin. Attackers can inject malicious scripts, which may be executed in the browsers of users who view the affected coupons. This poses significant risks, including unauthorized actions and data leakage, making it critical for site administrators to apply necessary updates to safeguard their websites.

Affected Version(s)

Flexible PDF Coupons < 1.10.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

savphill (Patchstack Alliance)
.