Cross-site Scripting Vulnerability in Astra Widgets by Brainstorm Force
CVE-2025-68497
5.4MEDIUM
What is CVE-2025-68497?
A vulnerability affecting Astra Widgets allows for improper neutralization of user inputs, leading to Stored Cross-site Scripting (XSS) issues. This can enable attackers to execute malicious scripts in the context of a web user's session. Users of Astra Widgets, especially those using versions 1.2.16 and earlier, should take immediate action to secure their installations and prevent potential exploitation of this flaw.
Affected Version(s)
Astra Widgets 0 <= 1.2.16