Cross-site Scripting Vulnerability in Khaled User Meta Plugin
CVE-2025-47611

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
23 May 2025

What is CVE-2025-47611?

The Khaled User Meta plugin for WordPress is susceptible to a Cross-site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts into web pages viewed by users. This vulnerability affects versions from n/a through 3.1.2, which could lead to reflected XSS attacks, compromising user data and security.

Affected Version(s)

User Meta <= 3.1.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

stealthcopter (Patchstack Alliance)
.
CVE-2025-47611 : Cross-site Scripting Vulnerability in Khaled User Meta Plugin