First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRUDLab CRUDLab Scroll to Top allows Reflected XSS. This issue affects CRUDLab Scroll to Top: from n/a through 1.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CRUDLab Scroll to Top | <=1.0.1 | |
CRUDLab Scroll to Top | <=1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22774 has a medium severity due to its potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-22774, upgrade CRUDLab Scroll to Top to version 1.0.2 or later.
CVE-2025-22774 allows attackers to inject malicious scripts into web pages, which can compromise user data.
CVE-2025-22774 affects CRUDLab Scroll to Top versions up to and including 1.0.1.
Yes, if you are using the CRUDLab Scroll to Top Plugin version 1.0.1 on WordPress, your site is susceptible to CVE-2025-22774.