CVE-2025-23579: WordPress DZS Ajaxer Lite plugin <= 1.04 - Cross Site Scripting (XSS) vulnerability
Published Mar 3, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio DZS Ajaxer Lite dzs-ajaxer-lite-dynamic-page-load allows Stored XSS.This issue affects DZS Ajaxer Lite: from n/a through <= 1.04.
Affected Software
1 affected component
Digitalzoomstudio DZS Ajaxer Lite<=1.04
Event History
Mar 3, 2025
CVE Published
via MITRE·01:30 PM
Data Sourced
via MITRE·01:30 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-23579?
CVE-2025-23579 has been identified as a Stored Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-23579?
To fix CVE-2025-23579, update DZS Ajaxer Lite to the latest version beyond 1.04.
3
What versions of DZS Ajaxer Lite are affected by CVE-2025-23579?
CVE-2025-23579 affects DZS Ajaxer Lite from an unspecified version up to and including 1.04.
4
What could happen if CVE-2025-23579 is exploited?
If CVE-2025-23579 is exploited, attackers could execute malicious scripts in the context of the affected user's browser.
5
Who is the vendor of the software related to CVE-2025-23579?
The vendor of the affected software is DZS.