First published: Fri Feb 14 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomáš Groulík Intro Tour Tutorial DeepPresentation allows Reflected XSS. This issue affects Intro Tour Tutorial DeepPresentation: from n/a through 6.5.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
DeepPresentation | >=n/a<6.5.2 | |
WordPress Intro Tour Tutorial DeepPresentation | <=6.5.2 |
Update the WordPress Intro Tour Tutorial DeepPresentation wordpress plugin to the latest available version (at least 6.5.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24566 has a moderate severity due to its potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-24566, update to the latest version of Intro Tour Tutorial DeepPresentation beyond version 6.5.2.
CVE-2025-24566 can facilitate reflected XSS attacks, which may allow attackers to execute scripts in the context of the user's browser.
CVE-2025-24566 affects users of the Intro Tour Tutorial DeepPresentation plugin from versions n/a to 6.5.2.
CVE-2025-24566 is a remote vulnerability, as it can be exploited by attackers without direct access to the affected system.