Code Injection Vulnerability in RadiusTheme Classified Listing by RadiusTheme
CVE-2025-54698
5.4MEDIUM
What is CVE-2025-54698?
A Cross-Site Scripting (XSS) vulnerability in the RadiusTheme Classified Listing plugin allows attackers to inject malicious scripts. This flaw affects versions from n/a up to 5.0.0, enabling unauthorized code execution through improper neutralization of script-related HTML tags in web pages. Users are advised to upgrade to the latest version and implement security best practices to mitigate potential risks.
Affected Version(s)
Classified Listing <= 5.0.0