CVE-2025-24646: WordPress XML for Avito Plugin <= 2.5.2 - Reflected Cross Site Scripting (XSS) vulnerability
Published Feb 3, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc XML for Avito xml-for-avito allows Reflected XSS.This issue affects XML for Avito: from n/a through <= 2.5.2.
Affected Software
1 affected component
Icopydoc WordPress XML for Avito<=2.5.2
Event History
Feb 3, 2025
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24646?
CVE-2025-24646 has a high severity level due to its potential for reflected cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-24646?
To fix CVE-2025-24646, update the XML for Avito plugin to version 2.5.3 or later.
3
Who is affected by CVE-2025-24646?
Users of the WordPress XML for Avito plugin version 2.5.2 and earlier are affected by CVE-2025-24646.
4
What type of vulnerability is CVE-2025-24646?
CVE-2025-24646 is a reflected cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2025-24646?
Attackers can exploit CVE-2025-24646 to execute arbitrary JavaScript in the context of a user's browser session.