First published: Tue Feb 25 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Info Cards – Gutenberg block for creating Beautiful Cards allows Stored XSS. This issue affects Info Cards – Gutenberg block for creating Beautiful Cards: from n/a through 1.0.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
bPlugins Info Cards | <=1.0.5 | |
WordPress Info Cards | <=1.0.5 |
Update the WordPress Info Cards – Gutenberg block for creating Beautiful Cards wordpress plugin to the latest available version (at least 1.0.6).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26945 is a critical vulnerability due to its potential for Stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-26945, update the Info Cards – Gutenberg block for creating Beautiful Cards to version 1.0.6 or later.
CVE-2025-26945 affects all versions of Info Cards – Gutenberg block for creating Beautiful Cards up to and including version 1.0.5.
CVE-2025-26945 allows attackers to execute arbitrary JavaScript in the context of a victim's browser, potentially leading to data theft or session hijacking.
Yes, the recommended action is to install the latest update for the affected plugin which resolves the vulnerability.