First published: Tue Feb 25 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup allows Stored XSS. This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through 5.21.35.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress EZ SQL Reports Shortcode Widget | <=5.21.35 | |
WordPress Database Backup | <=5.21.35 |
Update the WordPress EZ SQL Reports Shortcode Widget and DB Backup wordpress plugin to the latest available version (at least 5.25.08).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26887 is classified as a medium-severity vulnerability due to its potential for allowing stored cross-site scripting attacks.
To fix CVE-2025-26887, update the EZ SQL Reports Shortcode Widget and DB Backup plugins to the latest version beyond 5.21.35.
CVE-2025-26887 facilitates stored cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
CVE-2025-26887 affects versions of the EZ SQL Reports Shortcode Widget and DB Backup plugins from n/a up to and including 5.21.35.
Anyone using the affected versions of the EZ SQL Reports Shortcode Widget and DB Backup plugins on their WordPress sites is at risk of CVE-2025-26887.