First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TotalSuite TotalContest Lite allows Reflected XSS. This issue affects TotalContest Lite: from n/a through 2.8.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress TotalContest Lite Plugin | <=2.8.1 | |
WordPress TotalContest Lite Plugin | <=2.8.1 |
Update the WordPress TotalContest Lite plugin to the latest available version (at least 2.9.0).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23782 is classified as a High severity vulnerability due to its potential for Reflected Cross-site Scripting (XSS).
To fix CVE-2025-23782, update the TotalContest Lite plugin to version 2.8.2 or later, which addresses the vulnerability.
The risks include possible malicious scripts being executed in users' browsers, leading to data theft or unauthorized actions on behalf of users.
CVE-2025-23782 affects TotalContest Lite versions up to and including 2.8.1.
Yes, CVE-2025-23782 specifically affects the TotalContest Lite plugin for WordPress.