CVE-2025-26972: WordPress PrivateContent plugin <= 8.11.5 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent private-content.This issue affects PrivateContent: from n/a through <= 8.11.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26972?
The severity of CVE-2025-26972 is considered high due to its potential for Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-26972?
To fix CVE-2025-26972, upgrade the WordPress PrivateContent plugin to the latest version beyond 8.11.5.
What types of systems are affected by CVE-2025-26972?
CVE-2025-26972 affects WordPress installations running the PrivateContent plugin up to version 8.11.5.
What can an attacker do with CVE-2025-26972?
An attacker can exploit CVE-2025-26972 to execute malicious scripts in the context of a user's session, leading to data theft or other malicious actions.
Is CVE-2025-26972 under active exploitation?
As of now, there has been no confirmed active exploitation reported for CVE-2025-26972, but it is recommended to remediate the vulnerability promptly.