Cross-site Scripting Vulnerability in WPeka WP AdCenter
CVE-2025-53278

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 June 2025

What is CVE-2025-53278?

The WPeka WP AdCenter plugin suffers from a Cross-site Scripting vulnerability that permits attackers to inject malicious scripts through user inputs, which are improperly handled during web page generation. This security flaw affects versions up to 2.6.0, posing a risk of stored XSS attacks that could compromise a site's integrity and lead to unauthorized access or data manipulation. Website administrators are advised to update the plugin promptly to safeguard against potential exploits.

Affected Version(s)

WP AdCenter <= 2.6.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis (Patchstack Alliance)
.
CVE-2025-53278 : Cross-site Scripting Vulnerability in WPeka WP AdCenter