Cross-Site Scripting Vulnerability in bPlugins Team Section Block
CVE-2025-26949
6.5MEDIUM
What is CVE-2025-26949?
The Team Section Block by bPlugins is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper handling of user input during web page generation. This flaw allows attackers to inject malicious scripts that can execute in the context of other users, potentially leading to data theft, session hijacking, or malicious redirection. Affected versions range from n/a to 1.0.9, necessitating prompt attention to safeguard web applications utilizing this plugin.
Affected Version(s)
Team Section Block <= 1.0.9