Cross-site Scripting Vulnerability in CookieHint WP by reDim GmbH
CVE-2025-31608

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
31 March 2025

What is CVE-2025-31608?

A Cross-site Scripting (XSS) vulnerability exists in CookieHint WP by reDim GmbH. This flaw allows attackers to inject malicious scripts into web pages, affecting users who interact with compromised content. The vulnerability can be exploited through stored XSS, which means that the injected script can be permanently stored in the database. As a result, every time a page containing the payload is loaded, the malicious script executes in the user's browser, leading to potential data theft or unauthorized actions. It is crucial for users of CookieHint WP, especially those running versions from n/a to 1.0.0, to apply updates or implement security measures to mitigate the risk.

Affected Version(s)

CookieHint WP <= 1.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SOPROBRO (Patchstack Alliance)
.