Reflected XSS Vulnerability in Track, Analyze & Optimize by WP Tao
CVE-2025-48145
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 June 2025
What is CVE-2025-48145?
A Cross-site Scripting (XSS) vulnerability exists in Track, Analyze & Optimize by WP Tao, allowing attackers to inject malicious scripts into web pages viewed by other users. This reflected XSS issue impacts versions up to 1.3, enabling potential exploitation through unvalidated user input during web page generation. Website administrators should prioritize updating to secure web environments and ensure proper input sanitization practices to mitigate risks.
Affected Version(s)
Track, Analyze & Optimize by WP Tao <= 1.3