CVE-2025-22760: WordPress CodeBard Help Desk plugin <= 1.1.2 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jan 15, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Reflected XSS.This issue affects CodeBard Help Desk: from n/a through <= 1.1.2.
Affected Software
3 affected components
Codebard Codebard Help Desk Wordpress<=1.1.2
Codebard Help Desk<=1.1.2
WordPress CodeBard Help Desk plugin<=1.1.2
Event History
Jan 15, 2025
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22760?
CVE-2025-22760 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-22760?
To fix CVE-2025-22760, update the CodeBard Help Desk plugin to version 1.1.3 or later.
3
Which versions are affected by CVE-2025-22760?
CVE-2025-22760 affects CodeBard Help Desk plugin versions up to and including 1.1.2.
4
What type of vulnerability is CVE-2025-22760?
CVE-2025-22760 is an improper neutralization of input during web page generation that leads to cross-site scripting (XSS).
5
Who is the vendor for the affected software of CVE-2025-22760?
The vendor for the affected software is CodeBard, specifically for the CodeBard Help Desk plugin.