First published: Thu Jan 09 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.23.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Author Avatars List/Block | <=2.1.23 | |
Bearne Author Avatars List / Block | <=2.1.23 |
Update the WordPress Author Avatars List/Block wordpress plugin to the latest available version (at least 2.1.24).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-22804 is considered high due to its potential to allow stored cross-site scripting (XSS) attacks.
To fix CVE-2025-22804, you should update the Author Avatars List/Block plugin to version 2.1.24 or later.
CVE-2025-22804 affects the Paul Bearne Author Avatars List/Block plugin version 2.1.23 and below.
The potential consequences of CVE-2025-22804 include unauthorized access and manipulation of user data through XSS attacks.
CVE-2025-22804 exploits cross-site scripting vulnerabilities by improperly neutralizing user input during web page generation, allowing attackers to inject malicious scripts.