Cross-site Scripting Vulnerability in imaprogrammer Custom Comment Plugin
CVE-2025-48365
5.9MEDIUM
What is CVE-2025-48365?
The imaprogrammer Custom Comment plugin is vulnerable to Cross-site Scripting (XSS) due to improper validation of user input during web page generation. This vulnerability allows attackers to inject malicious scripts into comments, which can be executed in the context of a user's browser session. The issue impacts versions from n/a through 2.1.6, potentially allowing unauthorized actions such as session hijacking, phishing, or redirecting users to harmful websites. It is crucial for users of the plugin to implement immediate security measures or upgrade to a patched version to protect against this security flaw.
Affected Version(s)
Custom Comment <= 2.1.6
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nabil Irawan (Patchstack Alliance)