Reflected XSS Vulnerability in TC.K Advance WP Query Search Filter
CVE-2025-26743

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 April 2025

What is CVE-2025-26743?

A reflected cross-site scripting vulnerability exists in the TC.K Advance WP Query Search Filter plugin for WordPress. This vulnerability allows malicious actors to exploit improper input sanitization during web page generation. As a result, attackers can inject arbitrary JavaScript code into the web pages served to users, potentially compromising sensitive user data and leading to unauthorized actions on behalf of victims. This issue is present in versions of Advance WP Query Search Filter from n/a through 1.0.10, highlighting the importance of securing input handling to mitigate such threats.

Affected Version(s)

Advance WP Query Search Filter <= 1.0.10

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dimas Maulana (Patchstack Alliance)
.