First published: Thu Mar 27 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems ARPrice allows Stored XSS.This issue affects ARPrice: from n/a through 4.1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
ARPrice Lite | <=4.1.3 | |
WordPress ARPrice | <=4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26731 has a critical severity due to its potential for Stored XSS attacks.
To fix CVE-2025-26731, update Repute Infosystems ARPrice to the latest version beyond 4.1.3.
CVE-2025-26731 can lead to Stored Cross-Site Scripting (XSS) attacks, allowing attackers to execute malicious scripts.
CVE-2025-26731 affects all versions of ARPrice from n/a through 4.1.3.
While the exploitation rate can vary, stored XSS vulnerabilities such as CVE-2025-26731 are frequently targeted due to their impact.