Cross-site Scripting Vulnerability in Enfold Theme by Kriesi
CVE-2025-66053
6.5MEDIUM
What is CVE-2025-66053?
The Enfold theme by Kriesi is impacted by a Cross-site Scripting vulnerability that allows attackers to inject malicious scripts, facilitating Stored XSS attacks. This vulnerability affects versions of Enfold from an unspecified date up to and including version 7.1.2, potentially compromising the security of the web pages and users interacting with them. It underscores the need for timely updates and adequate web application security practices to mitigate such risks.
Affected Version(s)
Enfold <= n/a
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program