Cross-Site Scripting Vulnerability in AWStats Script by Jorge Garcia de Bustos
CVE-2025-49890

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2025

What is CVE-2025-49890?

A Cross-site Scripting (XSS) vulnerability exists in the AWStats Script developed by Jorge Garcia de Bustos. This vulnerability arises from improper neutralization of input during web page generation, allowing for stored XSS attacks. This could enable attackers to inject malicious scripts into web pages viewed by other users, potentially compromising sensitive information or hijacking user sessions. The issue affects the AWStats Script in all versions up to and including 0.3.

Affected Version(s)

Organic Beauty 0 <= 1.4.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.