Cross-Site Scripting Vulnerability in User Role Plugin by Ehabstar
CVE-2025-25114

7.1HIGH

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
3 March 2025

Summary

The User Role plugin by Ehabstar is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper input neutralization during web page generation. This vulnerability can be exploited to execute arbitrary scripts in the context of user sessions, leading to unauthorized actions or data exposure. This issue affects versions from n/a up to 1.0, and it's crucial for users to apply the necessary updates to mitigate potential risks.

Affected Version(s)

User Role <= 1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3 (Patchstack Alliance)
.