CVE-2025-22793: WordPress Bold pagos en linea Plugin <= 3.1.4 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jan 15, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bold Bold pagos en linea bold-pagos-en-linea allows DOM-Based XSS.This issue affects Bold pagos en linea: from n/a through <= 3.1.4.
Affected Software
1 affected component
Bold Bold pagos en linea<=3.1.4
Event History
Jan 15, 2025
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22793?
CVE-2025-22793 is classified as a Cross-site Scripting (XSS) vulnerability with a medium severity level.
2
How do I fix CVE-2025-22793?
To fix CVE-2025-22793, upgrade the Bold pagos en linea plugin to a version later than 3.1.0.
3
Who is affected by CVE-2025-22793?
CVE-2025-22793 affects users of the Bold pagos en linea plugin for WordPress version 3.1.0 and earlier.
4
What type of vulnerability is CVE-2025-22793?
CVE-2025-22793 is a DOM-Based Cross-site Scripting (XSS) vulnerability.
5
What software is impacted by CVE-2025-22793?
CVE-2025-22793 impacts the Bold pagos en linea plugin for WordPress versions up to and including 3.1.0.