Stored Cross-site Scripting in Nurelm Get Posts Plugin
CVE-2025-27349

6.5MEDIUM

Key Information:

Vendor
Nurelm
Status
Get Posts
Vendor
CVE Published:
24 February 2025

Summary

The Nurelm Get Posts plugin for WordPress contains a vulnerability that allows for stored cross-site scripting (XSS) attacks. This occurs due to improper handling of input during web page generation, enabling attackers to inject malicious scripts. Consequently, when users interact with the affected plugin, these scripts may execute in their browsers, potentially compromising their data and overall site security. It is imperative for users of the Nurelm Get Posts plugin to implement necessary updates and enhancements to protect their websites from exploitation.

Affected Version(s)

Get Posts <= 0.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.