First published: Mon Mar 03 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Theme Options Z allows Stored XSS. This issue affects Theme Options Z: from n/a through 1.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Theme Options Z Plugin | >=1.4 | |
WordPress Theme Options Z Plugin | <=1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25121 is classified as a high severity vulnerability due to its potential for Stored Cross-site Scripting (XSS).
To fix CVE-2025-25121, update NotFound Theme Options Z to version 1.4 or higher to mitigate the risk of Stored XSS.
CVE-2025-25121 affects all versions of NotFound Theme Options Z prior to and including version 1.4.
CVE-2025-25121 is an Improper Neutralization of Input During Web Page Generation, specifically a Stored Cross-site Scripting (XSS) vulnerability.
Users of NotFound Theme Options Z versions from n/a through 1.4 are impacted by CVE-2025-25121.