Cross-site Scripting Vulnerability in Pierre Lannoy's Sessions Plugin
CVE-2025-57890
5.9MEDIUM
What is CVE-2025-57890?
The Sessions plugin by Pierre Lannoy is impacted by a stored cross-site scripting (XSS) vulnerability that arises from improper treatment of user inputs during web page generation. This flaw can allow malicious users to inject harmful scripts into web pages viewed by other users. Versions from n/a to 3.2.0 are susceptible, making it crucial for users to apply necessary patches to safeguard against potential exploits.
Affected Version(s)
Sessions <= 3.2.0