First published: Thu Mar 27 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yudleethemes Whitish Lite allows Stored XSS.This issue affects Whitish Lite: from n/a through 2.1.13.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
yudleethemes Whitish Lite | <=2.1.13 | |
WordPress Whitish Lite | <=2.1.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22278 has been classified as a high-severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
To fix CVE-2025-22278, you should update the Whitish Lite theme to the latest version after 2.1.13.
CVE-2025-22278 can allow attackers to inject malicious scripts that may compromise the security and integrity of your website.
CVE-2025-22278 affects all versions of Whitish Lite from the beginning up to and including version 2.1.13.
Exploitation of CVE-2025-22278 does not require user interaction, making it a significant risk for impacted installations.