Cross-Site Scripting Vulnerability in OTWthemes Post Custom Templates Lite
CVE-2025-30942
5.9MEDIUM
What is CVE-2025-30942?
A Cross-Site Scripting (XSS) vulnerability exists in the OTWthemes Post Custom Templates Lite, enabling attackers to inject malicious scripts into web pages. This vulnerability affects versions ranging from n/a through 1.14, allowing the execution of unauthorized scripts when users interact with the compromised elements of the application. Such issues can lead to significant security breaches, including data theft and user session hijacking, revealing the necessity for immediate remediation.
Affected Version(s)
Post Custom Templates Lite <= 1.14
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Tran Tuan Dung (domiee13) (Patchstack Alliance)