Cross-site Scripting Vulnerability in Tiger Theme by Jocoxdesign
CVE-2025-31027

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
19 May 2025

What is CVE-2025-31027?

A cross-site scripting vulnerability exists within the Tiger Theme by Jocoxdesign, allowing attackers to inject malicious scripts. This reflected XSS issue can affect users by executing unwanted actions and potentially compromising sensitive information when they interact with the webpage. It is critical for users to be aware of the risk associated with the affected versions of the Tiger Theme, specifically from n/a through 2.0.

Affected Version(s)

Tiger <= 2.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.
CVE-2025-31027 : Cross-site Scripting Vulnerability in Tiger Theme by Jocoxdesign