CVE-2025-22790: WordPress moseter theme <= 1.3.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in asmedia allows Reflected XSS.This issue affects moseter: from n/a through 1.3.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in asmedia moseter moseter allows Reflected XSS.This issue affects moseter: from n/a through <= 1.3.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22790?
CVE-2025-22790 is classified as a moderate severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-22790?
To fix CVE-2025-22790, update the Asmedia Moseter or WordPress Moseter Theme to versions above 1.3.1.
What types of applications are affected by CVE-2025-22790?
CVE-2025-22790 affects the Asmedia Moseter and the WordPress Moseter Theme up to version 1.3.1.
What can attackers do with CVE-2025-22790?
Attackers can exploit CVE-2025-22790 to execute arbitrary scripts in a user's browser via reflected cross-site scripting.
Is there a known exploit for CVE-2025-22790?
Yes, CVE-2025-22790 has been documented as being exploitable through reflected XSS techniques.