Reflected XSS Vulnerability in Auto Scroll for Reading Plugin by WordPress
CVE-2025-31594
7.1HIGH
What is CVE-2025-31594?
The Auto Scroll for Reading plugin for WordPress is susceptible to reflected Cross-site Scripting (XSS) vulnerabilities due to improper input handling during web page generation. This can allow attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or session hijacking. The vulnerability affects versions from n/a up to and including 1.1.4, emphasizing the need for users to secure their sites by updating the plugin to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Auto scroll for reading <= 1.1.4
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published