Cross-site Scripting Vulnerability in AR For WordPress by Webandprint
CVE-2025-26913
6.5MEDIUM
Key Information:
- Vendor
- Webandprint
- Status
- Ar For WordPress
- Vendor
- CVE Published:
- 25 February 2025
Summary
A Cross-site Scripting vulnerability exists in the AR For WordPress plugin, allowing attackers to execute arbitrary JavaScript code in the context of the user's browser. This issue arises from improper neutralization of input during web page generation, specifically within the plugin's handling of user-supplied data. As a result, malicious actors can exploit this weakness to create dynamic content that leads to user sessions hijacking, unauthorized actions, or data theft. Vulnerable versions include those from unassigned through 7.7.
Affected Version(s)
AR For WordPress <= 7.7
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)