Stored XSS Vulnerability in Breaking News WP Plugin by WordPress
CVE-2025-31750

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 April 2025

What is CVE-2025-31750?

The Breaking News WP plugin for WordPress is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. This security flaw allows attackers to inject malicious scripts into web pages that are then delivered to users. Affected versions include those prior to and including 1.3. Proper validation and sanitization of user input have not been implemented, leading to potential exploitation on web applications relying on this plugin. Website administrators using the Breaking News WP plugin should take immediate action to address this vulnerability to protect their sites and users.

Affected Version(s)

Breaking News WP <= 1.3

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.