Stored Cross-site Scripting Vulnerability in Better WishList API by rickonline_nl
CVE-2025-24641
7.1HIGH
Summary
The Better WishList API plugin by rickonline_nl contains a vulnerability due to improper neutralization of input during web page generation, which can lead to Stored Cross-site Scripting (XSS). This vulnerability could allow attackers to inject malicious scripts into pages viewed by users, compromising data integrity and exposing sensitive information. The issue affects all versions of the Better WishList API up to and including version 1.1.3.
Affected Version(s)
Better WishList API <= 1.1.3
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)