First published: Tue Jan 07 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sw-galati.ro iframe to embed allows Stored XSS.This issue affects iframe to embed: from n/a through 1.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
sw-galati.ro iframe to embed | >=n/a<1.2 | |
WordPress iframe to embed plugin | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22545 is a high-severity vulnerability due to its potential for enabling stored cross-site scripting (XSS).
To fix CVE-2025-22545, update the sw-galati.ro iframe to embed to the latest version beyond 1.2 if available.
CVE-2025-22545 affects sw-galati.ro iframe to embed and the WordPress iframe to embed plugin up to version 1.2.
CVE-2025-22545 is an improper neutralization of input vulnerability, specifically allowing for stored cross-site scripting (XSS).
Yes, CVE-2025-22545 can potentially lead to data theft if exploited, as it allows attackers to execute malicious scripts in the context of a user's session.