Stored XSS Vulnerability in Breaking News WP Plugin by WordPress
CVE-2025-31750
5.9MEDIUM
What is CVE-2025-31750?
The Breaking News WP plugin for WordPress is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. This security flaw allows attackers to inject malicious scripts into web pages that are then delivered to users. Affected versions include those prior to and including 1.3. Proper validation and sanitization of user input have not been implemented, leading to potential exploitation on web applications relying on this plugin. Website administrators using the Breaking News WP plugin should take immediate action to address this vulnerability to protect their sites and users.
Affected Version(s)
Breaking News WP <= 1.3