Cross-Site Scripting Vulnerability in OTWthemes Post Custom Templates Lite
CVE-2025-30942

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2025

What is CVE-2025-30942?

A Cross-Site Scripting (XSS) vulnerability exists in the OTWthemes Post Custom Templates Lite, enabling attackers to inject malicious scripts into web pages. This vulnerability affects versions ranging from n/a through 1.14, allowing the execution of unauthorized scripts when users interact with the compromised elements of the application. Such issues can lead to significant security breaches, including data theft and user session hijacking, revealing the necessity for immediate remediation.

Affected Version(s)

Post Custom Templates Lite <= 1.14

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Tran Tuan Dung (domiee13) (Patchstack Alliance)
.