Cross-site Scripting Vulnerability in imaprogrammer Custom Comment Plugin
CVE-2025-48365

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 August 2025

What is CVE-2025-48365?

The imaprogrammer Custom Comment plugin is vulnerable to Cross-site Scripting (XSS) due to improper validation of user input during web page generation. This vulnerability allows attackers to inject malicious scripts into comments, which can be executed in the context of a user's browser session. The issue impacts versions from n/a through 2.1.6, potentially allowing unauthorized actions such as session hijacking, phishing, or redirecting users to harmful websites. It is crucial for users of the plugin to implement immediate security measures or upgrade to a patched version to protect against this security flaw.

Affected Version(s)

Custom Comment <= 2.1.6

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.
CVE-2025-48365 : Cross-site Scripting Vulnerability in imaprogrammer Custom Comment Plugin