CVE-2025-1523: Ultimate Dashboard < 3.8.6 - Admin+ Stored XSS
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1523?
CVE-2025-1523 is considered a medium severity vulnerability due to the potential for stored Cross-Site Scripting attacks.
How do I fix CVE-2025-1523?
To fix CVE-2025-1523, update the Ultimate Dashboard plugin to version 3.8.6 or later.
Who is affected by CVE-2025-1523?
High privilege users, such as administrators of WordPress sites using the Ultimate Dashboard plugin version before 3.8.6, are affected by CVE-2025-1523.
What types of attacks can CVE-2025-1523 allow?
CVE-2025-1523 can allow high privilege users to perform stored Cross-Site Scripting attacks.
What are the consequences of CVE-2025-1523?
The consequences of CVE-2025-1523 may include unauthorized execution of scripts in the context of users visiting the affected site.