Cross-site Scripting Vulnerability in Melipayamak by Melipayamak
CVE-2025-30940

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2025

Badges

👾 Exploit Exists📰 News Worthy

What is CVE-2025-30940?

The Melipayamak platform is impacted by a severe Cross-site Scripting (XSS) vulnerability that arises from improper input neutralization during web page generation. This weakness allows attackers to inject malicious scripts, potentially compromising user data and web application security. Affected versions include all versions leading up to and including 2.2.12. Malicious users can exploit this flaw, leading to stored XSS issues that can affect sensitive user interactions and data integrity.

Affected Version(s)

Melipayamak <= 2.2.12

News Articles

CVE-2025-30940: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in melipayamak Melipayamak - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2025-30940: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in melipayamak Melipayama

1 week ago

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by OffSeq

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.
CVE-2025-30940 : Cross-site Scripting Vulnerability in Melipayamak by Melipayamak