CVE-2025-22757: WordPress CodeBard Help Desk plugin <= 1.1.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Stored XSS.This issue affects CodeBard Help Desk: from n/a through <= 1.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22757?
CVE-2025-22757 has a high severity level due to its potential to allow stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-22757?
To fix CVE-2025-22757, update the CodeBard Help Desk plugin to version 1.1.3 or later, where the vulnerability is patched.
What is the impact of CVE-2025-22757 on affected systems?
CVE-2025-22757 can lead to unauthorized execution of malicious scripts in users' browsers, compromising sensitive information.
Which versions of CodeBard Help Desk are affected by CVE-2025-22757?
CVE-2025-22757 affects all versions of CodeBard Help Desk up to and including version 1.1.2.
Is there a proof of concept for CVE-2025-22757?
As of now, detailed proof of concept demonstrations for CVE-2025-22757 have not been publicly released.