Cross-site Scripting Vulnerability in Google Drive WP Media Plugin by Moch Amir
CVE-2025-26574
6.5MEDIUM
What is CVE-2025-26574?
The Google Drive WP Media plugin by Moch Amir is vulnerable to a Cross-site Scripting (XSS) issue, which occurs due to improper neutralization of user input during web page generation. This vulnerability allows for the execution of malicious scripts in the context of a victim's browser, leading to potential data theft and site compromise. The affected versions range from n/a through 2.4.4, highlighting the importance of maintaining updated software to guard against such security risks.
Affected Version(s)
Google Drive WP Media 0 <= 2.4.4