Cross-site Scripting Vulnerability in imaprogrammer Custom Comment Plugin
CVE-2025-48365
What is CVE-2025-48365?
The imaprogrammer Custom Comment plugin is vulnerable to Cross-site Scripting (XSS) due to improper validation of user input during web page generation. This vulnerability allows attackers to inject malicious scripts into comments, which can be executed in the context of a user's browser session. The issue impacts versions from n/a through 2.1.6, potentially allowing unauthorized actions such as session hijacking, phishing, or redirecting users to harmful websites. It is crucial for users of the plugin to implement immediate security measures or upgrade to a patched version to protect against this security flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Custom Comment <= 2.1.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved