First published: Fri Feb 07 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Mark Barnes Style Tweaker allows Stored XSS. This issue affects Style Tweaker: from n/a through 0.11.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Markbarnes Style Tweaker | <=0.11 | |
Markbarnes Style Tweaker | >=0.11 | |
WordPress Style Tweaker | <=0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25160 is classified as a critical severity vulnerability due to its potential for causing stored cross-site scripting (XSS) attacks.
To fix CVE-2025-25160, update the Mark Barnes Style Tweaker or WordPress Style Tweaker plugin to the latest version that addresses this vulnerability.
CVE-2025-25160 affects versions of Mark Barnes Style Tweaker and WordPress Style Tweaker from n/a through 0.11.
CVE-2025-25160 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to stored XSS attacks.
If your website is using Mark Barnes Style Tweaker or WordPress Style Tweaker versions 0.11 or lower, it is vulnerable to CVE-2025-25160.