First published: Thu Jan 16 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jens Remus WP krpano allows Stored XSS.This issue affects WP krpano: from n/a through 1.2.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
krpano | <=1.2.1 | |
krpano | <=1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23876 is classified as a stored cross-site scripting (XSS) vulnerability, which can lead to significant security risks including data theft and user impersonation.
To mitigate CVE-2025-23876, update the WP krpano plugin to version 1.2.2 or later, which resolves the vulnerability.
CVE-2025-23876 affects all versions of WP krpano up to and including version 1.2.1.
The potential impacts of CVE-2025-23876 include unauthorized access to user data and execution of malicious scripts in the context of a user's browser.
The vendor for CVE-2025-23876 is Jens Remus, associated with the WP krpano plugin.