CVE-2025-23992: WordPress Toocheke Companion plugin <= 1.166 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke Companion toocheke-companion allows Stored XSS.This issue affects Toocheke Companion: from n/a through <= 1.166.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23992?
CVE-2025-23992 is classified as a high-severity vulnerability due to its potential for exploitation via Stored Cross-Site Scripting (XSS).
How do I fix CVE-2025-23992?
To fix CVE-2025-23992, update Leetoo Toocheke Companion to version 1.167 or higher immediately.
What types of systems are impacted by CVE-2025-23992?
CVE-2025-23992 affects Leetoo Toocheke Companion versions up to and including 1.166, as well as WordPress Toocheke Companion in the same version range.
What is the nature of the vulnerability in CVE-2025-23992?
CVE-2025-23992 involves improper neutralization of input during web page generation, allowing for Stored XSS attacks.
Can CVE-2025-23992 be exploited remotely?
Yes, CVE-2025-23992 can be exploited remotely, making it critical to patch affected systems as soon as possible.