CVE-2025-26751: WordPress Alphabetic Pagination Plugin <= 3.2.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood Alphabetic Pagination alphabetic-pagination allows Reflected XSS.This issue affects Alphabetic Pagination: from n/a through <= 3.2.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26751?
CVE-2025-26751 has been classified as a high-severity vulnerability due to its potential for allowing reflected cross-site scripting (XSS).
How do I fix CVE-2025-26751?
To fix CVE-2025-26751, update the Fahad Mahmood Alphabetic Pagination plugin to version 3.2.2 or later.
What is the impact of CVE-2025-26751?
CVE-2025-26751 can lead to exploited reflected XSS, allowing attackers to execute scripts in the context of users' browsers.
Who is affected by CVE-2025-26751?
CVE-2025-26751 affects users of Fahad Mahmood Alphabetic Pagination and WordPress Alphabetic Pagination Plugin versions up to 3.2.1.
Is there a patch available for CVE-2025-26751?
Yes, a patch is available by updating to the latest version of the Alphabetic Pagination plugin.