Stored Cross-site Scripting in Nurelm Get Posts Plugin
CVE-2025-27349
6.5MEDIUM
Key Information:
- Vendor
- Nurelm
- Status
- Get Posts
- Vendor
- CVE Published:
- 24 February 2025
Summary
The Nurelm Get Posts plugin for WordPress contains a vulnerability that allows for stored cross-site scripting (XSS) attacks. This occurs due to improper handling of input during web page generation, enabling attackers to inject malicious scripts. Consequently, when users interact with the affected plugin, these scripts may execute in their browsers, potentially compromising their data and overall site security. It is imperative for users of the Nurelm Get Posts plugin to implement necessary updates and enhancements to protect their websites from exploitation.
Affected Version(s)
Get Posts <= 0.6
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
theviper17 (Patchstack Alliance)