First published: Sat Feb 22 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic the Gathering Card Tooltips allows Stored XSS. This issue affects Magic the Gathering Card Tooltips: from n/a through 3.5.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
>=n/a<=3.5.0 | ||
<=3.5.0 |
Update the WordPress Magic the Gathering Card Tooltips plugin to the latest available version (at least 3.6.0).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26756 is classified as a stored Cross-site Scripting (XSS) vulnerability which can lead to severe impacts depending on the exploit.
To fix CVE-2025-26756, update the Magic the Gathering Card Tooltips to version 3.5.1 or later where the vulnerability has been addressed.
CVE-2025-26756 affects versions of Magic the Gathering Card Tooltips from n/a through 3.5.0.
CVE-2025-26756 specifically allows for stored Cross-site Scripting (XSS) which could lead to further attacks.
The vendor responsible for addressing CVE-2025-26756 is Grimdonkey, associated with the Magic the Gathering Card Tooltips.