CVE-2025-22709: WordPress Verge3D Publishing and E-Commerce Plugin <= 4.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jan 21, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D verge3d allows Reflected XSS.This issue affects Verge3D: from n/a through <= 4.8.0.
Affected Software
2 affected components
Soft8Soft Verge3D<=4.8.0
Soft8Soft WordPress Verge3D Publishing and E-Commerce Plugin<=4.8.0
Remediation
Information
Update the WordPress Verge3D wordpress plugin to the latest available version (at least 4.8.1).
Event History
Jan 21, 2025
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22709?
CVE-2025-22709 is considered a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-22709?
To fix CVE-2025-22709, update your Soft8Soft LLC Verge3D software to version 4.8.1 or later.
3
What versions are affected by CVE-2025-22709?
CVE-2025-22709 affects all versions of Verge3D from the initial release up to and including version 4.8.0.
4
What type of vulnerability is CVE-2025-22709?
CVE-2025-22709 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2025-22709 be exploited remotely?
Yes, CVE-2025-22709 can be exploited remotely by an attacker through malicious web links.