First published: Sun Feb 16 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka allows Stored XSS. This issue affects Leyka: from n/a through 3.31.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
VaultDweller Leyka | <=3.31.8 | |
WordPress Leyka plugin | <=3.31.8 |
Update the WordPress Leyka plugin to the latest available version (at least 3.31.9).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26766 is classified as a high severity vulnerability due to the risk of stored cross-site scripting (XSS) attacks.
CVE-2025-26766 affects VaultDweller Leyka versions up to and including 3.31.8.
To fix CVE-2025-26766, upgrade to a patched version of VaultDweller Leyka or the WordPress Leyka plugin that addresses this vulnerability.
CVE-2025-26766 is a stored cross-site scripting (XSS) vulnerability affecting web applications.
Yes, CVE-2025-26766 can be exploited remotely by an attacker using malicious input to execute scripts in the context of the user's session.