CVE-2025-23995: WordPress Tantyyellow theme <= 1.0.0.5 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ta2g Tantyyellow allows Reflected XSS.This issue affects Tantyyellow: from n/a through 1.0.0.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ta2g Tantyyellow tantyyellow allows Reflected XSS.This issue affects Tantyyellow: from n/a through <= 1.0.0.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23995?
CVE-2025-23995 is classified as a medium severity vulnerability due to the potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-23995?
To fix CVE-2025-23995, upgrade to a version of Tantyyellow beyond 1.0.0.5 where the vulnerability has been addressed.
What types of attacks can CVE-2025-23995 facilitate?
CVE-2025-23995 can facilitate reflected cross-site scripting (XSS) attacks, potentially allowing attackers to execute malicious scripts in the user's browser.
Which versions of Tantyyellow are affected by CVE-2025-23995?
CVE-2025-23995 affects all versions of Tantyyellow up to and including 1.0.0.5.
Does CVE-2025-23995 affect WordPress installations?
Yes, CVE-2025-23995 affects the Tantyyellow theme for WordPress versions up to and including 1.0.0.5.