Cross-site Scripting Vulnerability in Pootlepress Mobile Pages by WordPress
CVE-2025-32625

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 April 2025

What is CVE-2025-32625?

The Pootlepress Mobile Pages plugin for WordPress is susceptible to Cross-site Scripting (XSS) flaws due to improper input handling during web page generation. This vulnerability allows attackers to inject malicious scripts into the pages, affecting users who interact with the compromised content. Specifically, this issue can be exploited through reflected XSS, presenting a potential risk to both website operators and visitors. The affected versions range from n/a through 1.0.2, underscoring the need for prompt updates and remediation to enhance security.

Affected Version(s)

Mobile Pages <= 1.0.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.