Stored XSS Vulnerability in Drivr Lite – Google Drive Plugin by awsm.in
CVE-2025-27016
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 February 2025
What is CVE-2025-27016?
A vulnerability in the Drivr Lite – Google Drive Plugin by awsm.in enables attackers to execute stored cross-site scripting (XSS) attacks. This flaw occurs due to improper handling of user input while generating web pages, allowing malicious scripts to be stored and later executed in the context of a victim's session. Affected versions include n/a through 1.0.1, making it crucial for users to apply the necessary patches to safeguard their websites against potential exploits.
Affected Version(s)
Drivr Lite – Google Drive Plugin <= 1.0.1