Cross-site Scripting Vulnerability in DELUCKS SEO by DELUCKS
CVE-2025-47686

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 May 2025

What is CVE-2025-47686?

The vulnerability allows for improper neutralization of input during web page generation, facilitating stored Cross-site Scripting (XSS) attacks in DELUCKS SEO. This security flaw affects versions of DELUCKS SEO from n/a to 2.5.9, enabling unauthorized users to inject malicious scripts into web pages, compromising user data and security. Addressing this vulnerability is crucial for maintaining the integrity of web applications and protecting users from potential exploits.

Affected Version(s)

DELUCKS SEO <= 2.5.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

muhammad yudha (Patchstack Alliance)
.