Cross-site Scripting Vulnerability in FasterThemes FastBook
CVE-2025-25173

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
27 June 2025

What is CVE-2025-25173?

The FastBook plugin by FasterThemes contains a vulnerability that allows for Stored Cross-site Scripting (XSS) due to improper input neutralization during web page generation. Attackers could potentially exploit this weakness to inject malicious scripts, which may then be executed in the context of a victim's browser. This vulnerability affects FastBook versions up to 1.1, necessitating immediate attention from users to secure their installations.

Affected Version(s)

FastBook <= 1.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HLog (Patchstack Alliance)
.
CVE-2025-25173 : Cross-site Scripting Vulnerability in FasterThemes FastBook