Cross-site Scripting Vulnerability in AR For WordPress by Webandprint
CVE-2025-26913

6.5MEDIUM

Key Information:

Vendor
Webandprint
Status
Ar For WordPress
Vendor
CVE Published:
25 February 2025

Summary

A Cross-site Scripting vulnerability exists in the AR For WordPress plugin, allowing attackers to execute arbitrary JavaScript code in the context of the user's browser. This issue arises from improper neutralization of input during web page generation, specifically within the plugin's handling of user-supplied data. As a result, malicious actors can exploit this weakness to create dynamic content that leads to user sessions hijacking, unauthorized actions, or data theft. Vulnerable versions include those from unassigned through 7.7.

Affected Version(s)

AR For WordPress <= 7.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)
.