First published: Fri Jan 31 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGlow Cleanup – Directory Listing & Classifieds WordPress Plugin allows Reflected XSS. This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through 1.0.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
ThemeGlow Cleanup – Directory Listing & Classifieds WordPress Plugin | <=1.0.4 |
Update the WordPress Cleanup – Directory Listing & Classifieds WordPress Plugin wordpress plugin to the latest available version (at least 1.0.5).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24563 is classified as a moderate severity vulnerability due to its potential for reflected cross-site scripting.
To mitigate CVE-2025-24563, update the Cleanup – Directory Listing & Classifieds WordPress Plugin to version 1.0.5 or later.
CVE-2025-24563 can facilitate reflected cross-site scripting attacks that may lead to the execution of malicious scripts in users' browsers.
Yes, CVE-2025-24563 can be exploited without user interaction by tricking users into clicking on specially crafted links.
CVE-2025-24563 affects all versions of Cleanup – Directory Listing & Classifieds WordPress Plugin up to and including version 1.0.4.