Stored XSS Vulnerability in Rollover Tab by Eiji Yamada
CVE-2025-23863
6.5MEDIUM
Summary
The Rollover Tab plugin developed by Eiji ‘Sabaoh’ Yamada features a Stored Cross-site Scripting (XSS) vulnerability. This security flaw arises from improper handling of user input during web page generation, allowing an attacker to inject malicious scripts. Users of Rollover Tab versions up to and including 1.3.2 are particularly at risk, as the vulnerability can lead to unauthorized access and manipulation of user data, severely compromising the security of affected WordPress sites.
Affected Version(s)
Rollover Tab <= 1.3.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SOPROBRO (Patchstack Alliance)