Stored XSS Vulnerability in Rollover Tab by Eiji Yamada
CVE-2025-23863

6.5MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
16 January 2025

Summary

The Rollover Tab plugin developed by Eiji ‘Sabaoh’ Yamada features a Stored Cross-site Scripting (XSS) vulnerability. This security flaw arises from improper handling of user input during web page generation, allowing an attacker to inject malicious scripts. Users of Rollover Tab versions up to and including 1.3.2 are particularly at risk, as the vulnerability can lead to unauthorized access and manipulation of user data, severely compromising the security of affected WordPress sites.

Affected Version(s)

Rollover Tab <= 1.3.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SOPROBRO (Patchstack Alliance)
.