Reflected XSS Vulnerability in Basteln3rk Save & Import Image from URL Plugin
CVE-2025-23960
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 January 2025
What is CVE-2025-23960?
The Save & Import Image from URL plugin by Basteln3rk contains a vulnerability that allows for Reflected Cross-site Scripting (XSS). This weakness permits attackers to inject malicious scripts through improperly sanitized input during web page generation. The affected versions of the plugin could expose users to harmful exploits, potentially compromising user data and session integrity. It is crucial for users of this plugin to review their installations and apply necessary updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Save & Import Image from URL <= 0.7
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)