Stored Cross-site Scripting Vulnerability in Better WishList API by rickonline_nl
CVE-2025-24641

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
14 February 2025

Summary

The Better WishList API plugin by rickonline_nl contains a vulnerability due to improper neutralization of input during web page generation, which can lead to Stored Cross-site Scripting (XSS). This vulnerability could allow attackers to inject malicious scripts into pages viewed by users, compromising data integrity and exposing sensitive information. The issue affects all versions of the Better WishList API up to and including version 1.1.3.

Affected Version(s)

Better WishList API <= 1.1.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.