First published: Tue Feb 25 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webandprint AR For WordPress allows DOM-Based XSS. This issue affects AR For WordPress: from n/a through 7.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
webandprint AR For WordPress | <=7.7 | |
ARForms | <=7.7 |
Update the WordPress AR For WordPress plugin to the latest available version (at least 7.8).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26913 is classified as a high-severity vulnerability due to its potential for DOM-based cross-site scripting (XSS).
To fix CVE-2025-26913, update the AR For WordPress plugin to version 7.8 or later, which addresses the vulnerability.
CVE-2025-26913 affects all versions of the AR For WordPress plugin up to and including version 7.7.
CVE-2025-26913 is an improper neutralization of input during web page generation, known as cross-site scripting (XSS).
CVE-2025-26913 can allow attackers to execute arbitrary JavaScript in the context of a user's session, potentially leading to data theft or session hijacking.