Cross-Site Scripting Vulnerability in Hive Support Plugin by WordPress
CVE-2025-32214
6.5MEDIUM
What is CVE-2025-32214?
The Hive Support plugin for WordPress is susceptible to Cross-Site Scripting (XSS) attacks due to improper input handling during web page generation. This vulnerability could allow attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft and unauthorized actions. The issue affects all versions of Hive Support up to and including 1.2.2, necessitating immediate updates to maintain site security.
Affected Version(s)
Hive Support <= 1.2.2