Cross-site Scripting Vulnerability in Simply Guest Author Name Plugin by A. Jones
CVE-2025-24764
6.5MEDIUM
What is CVE-2025-24764?
A Cross-site Scripting (XSS) vulnerability exists in the Simply Guest Author Name plugin developed by A. Jones. This flaw allows attackers to execute arbitrary JavaScript code in the context of other users' browsers, potentially leading to session hijacking, redirection to malicious sites, or unauthorized data access. The vulnerability affects versions from n/a up to 4.36, emphasizing the need for immediate updates to prevent exploitation.
Affected Version(s)
(Simply) Guest Author Name <= 4.36