Cross-Site Scripting Vulnerability in Widget Logic Visual by TotalBounty
CVE-2025-68842
7.1HIGH
What is CVE-2025-68842?
The Widget Logic Visual plugin by TotalBounty is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability. This flaw enables attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions within the context of the user's session. This vulnerability affects versions of Widget Logic Visual up to and including 1.52, highlighting the importance for users to update to patched versions to mitigate the risk.
Affected Version(s)
Widget Logic Visual 0 <= 1.52