Cross-Site Scripting Vulnerability in CC Circle Progress Bar by Harun R. Rayhan
CVE-2025-23936
6.5MEDIUM
What is CVE-2025-23936?
The CC Circle Progress Bar plugin, developed by Harun R. Rayhan, is susceptible to stored Cross-Site Scripting (XSS) attacks due to improper neutralization of input during web page generation. This vulnerability allows attackers to inject malicious scripts, which can execute in the context of users visiting the affected webpage. Consequently, this could lead to data theft, session hijacking, and other malicious actions that compromise the security of the site and its users.
Affected Version(s)
CC Circle Progress Bar <= 1.0.0