Stored Cross-Site Scripting Vulnerability in FuseDesk WordPress Plugin
CVE-2025-3832
6.4MEDIUM
What is CVE-2025-3832?
The FuseDesk plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the 'successredirect' parameter. This flaw arises from inadequate input sanitization and output escaping in all versions up to and including 6.7. Attackers with Contributor-level access or higher can exploit this issue to inject arbitrary web scripts, which will execute whenever other users access the compromised pages.
Affected Version(s)
FuseDesk * <= 6.7