CVE-2025-22315: WordPress Typing Text plugin <= 1.2.7 - Cross Site Scripting (XSS) vulnerability
Published Jan 7, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Typing Text typing-text allows Stored XSS.This issue affects Typing Text: from n/a through <= 1.2.7.
Affected Software
3 affected components
WPDeveloper Typing Text<=1.2.7
WordPress Typing Text<=1.2.7
WPDeveloper Typing Text Wordpress<=1.2.7
Event History
Jan 7, 2025
CVE Published
via MITRE·10:48 AM
Data Sourced
via MITRE·10:48 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Jul 13, 58219
Event
via NVD·02:55 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-22315?
CVE-2025-22315 has a high severity due to its potential for Stored XSS attacks.
2
How do I fix CVE-2025-22315?
To fix CVE-2025-22315, update the WPDeveloper Typing Text plugin to version 1.2.8 or later.
3
What versions are affected by CVE-2025-22315?
CVE-2025-22315 affects WPDeveloper Typing Text versions from n/a through 1.2.7.
4
What type of vulnerability is CVE-2025-22315?
CVE-2025-22315 is a Cross-site Scripting (XSS) vulnerability.
5
Can CVE-2025-22315 lead to data theft?
Yes, CVE-2025-22315 can lead to data theft if an attacker exploits the Stored XSS vulnerability.