First published: Fri Feb 07 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robert_kolatzek WP doodlez allows Stored XSS. This issue affects WP doodlez: from n/a through 1.0.10.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WP doodlez | <=1.0.10 | |
WordPress WP Doodlez | <=1.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25159 is classified as a medium-severity vulnerability due to its potential for stored cross-site scripting attacks.
To fix CVE-2025-25159, update the WP doodlez plugin to the latest version beyond 1.0.10.
CVE-2025-25159 can allow attackers to inject malicious scripts that may steal user information or compromise user sessions.
CVE-2025-25159 affects all versions of WP doodlez from n/a through 1.0.10.
CVE-2025-25159 is specifically linked to the WP doodlez plugin and is not dependent on broader WordPress configurations.