CVE-2025-23986: WordPress Tiki Time theme <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyrewurks Tiki Time allows Reflected XSS.This issue affects Tiki Time: from n/a through 1.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyrewurks Tiki Time tiki-time allows Reflected XSS.This issue affects Tiki Time: from n/a through <= 1.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23986?
CVE-2025-23986 has been classified as a high severity reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-23986?
To fix CVE-2025-23986, update your fyrewurks Tiki Time installation to version 1.4 or later.
Which versions of fyrewurks Tiki Time are affected by CVE-2025-23986?
fyrewurks Tiki Time versions from n/a through 1.3 are affected by CVE-2025-23986.
Is WordPress Tiki Time theme vulnerable to CVE-2025-23986?
Yes, the WordPress Tiki Time theme versions up to and including 1.3 are vulnerable to CVE-2025-23986.
What type of vulnerability is CVE-2025-23986?
CVE-2025-23986 is an improper neutralization of input during web page generation, resulting in a reflected XSS vulnerability.