First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vicente Ruiz Gálvez VR-Frases allows Reflected XSS. This issue affects VR-Frases: from n/a through 3.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
VR-Frases | >n/a<=3.0.1 | |
VR-Frases | <=3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22636 has a medium severity level due to its potential for reflected XSS attacks.
To fix CVE-2025-22636, update VR-Frases to the latest version beyond 3.0.1 provided by Vicente Ruiz Gálvez.
CVE-2025-22636 affects both Vicente Ruiz Gálvez VR-Frases and WordPress VR-Frases versions from n/a to 3.0.1.
Attackers exploiting CVE-2025-22636 can execute arbitrary scripts on the user's browser via reflected XSS.
Yes, CVE-2025-22636 involves improper neutralization of user input during web page generation, leading to security vulnerabilities.