CVE-2025-22360: WordPress WP Azure offload plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Azure offload allows Reflected XSS. This issue affects WP Azure offload: from n/a through 2.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in promact WP Azure offload wp-azure-offload allows Reflected XSS.This issue affects WP Azure offload: from n/a through <= 2.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22360?
CVE-2025-22360 is classified as a reflected cross-site scripting (XSS) vulnerability in WP Azure offload.
How do I fix CVE-2025-22360?
To fix CVE-2025-22360, update the WP Azure offload plugin to the latest version beyond 2.0.
Who is affected by CVE-2025-22360?
CVE-2025-22360 affects all versions of the WP Azure offload plugin up to and including version 2.0.
What type of attacks can exploit CVE-2025-22360?
CVE-2025-22360 can be exploited through reflected XSS attacks, allowing attackers to execute arbitrary scripts in users' browsers.
What is the impact of CVE-2025-22360 on my website?
The impact of CVE-2025-22360 can include unauthorized access or manipulation of user data, session hijacking, or defacement of the website.