CVE-2025-22687: WordPress tuaug4 theme <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asmedia Tuaug4 allows Reflected XSS.This issue affects Tuaug4: from n/a through 1.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asmedia Tuaug4 tuaug4 allows Reflected XSS.This issue affects Tuaug4: from n/a through <= 1.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22687?
CVE-2025-22687 is identified as a reflected Cross-site Scripting (XSS) vulnerability in Asmedia Tuaug4.
How do I fix CVE-2025-22687?
To fix CVE-2025-22687, upgrade Asmedia Tuaug4 to a version later than 1.4.
Which versions of Asmedia Tuaug4 are affected by CVE-2025-22687?
CVE-2025-22687 affects Asmedia Tuaug4 versions up to and including 1.4.
Can CVE-2025-22687 affect WordPress themes?
Yes, CVE-2025-22687 also affects the WordPress tuaug4 theme version 1.4.
What exploit does CVE-2025-22687 allow for?
CVE-2025-22687 allows for reflected XSS attacks, enabling attackers to execute malicious scripts in a user's browser.