Code Injection Vulnerability in RS WP Book Showcase by RS WP THEMES
CVE-2025-48119

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 May 2025

What is CVE-2025-48119?

An improper control of code generation vulnerability has been identified in the RS WP Book Showcase plugin by RS WP THEMES. This flaw allows cybercriminals to inject arbitrary code, enabling them to execute malicious scripts and potentially compromise user data. This issue specifically affects the plugin versions ranging from n/a to 6.7.41. Users of this plugin should take immediate action to secure their installations against potential exploitation.

Affected Version(s)

RS WP Book Showcase <= 6.7.41

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.