First published: Wed Mar 26 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hostiko allows Reflected XSS.This issue affects Hostiko: from n/a before 30.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hostiko | <30.1 | |
WordPress Hostiko Theme | <30.1 |
Update the WordPress Hostiko wordpress theme to the latest available version (at least 30.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27014 is classified as a reflected Cross-site Scripting (XSS) vulnerability, which can have a moderate to high severity depending on the exploit context.
To fix CVE-2025-27014, upgrade the Hostiko software to version 30.1 or later, where the vulnerability has been addressed.
CVE-2025-27014 affects users of the Hostiko software version prior to 30.1, including the WordPress Hostiko Theme.
Reflected XSS, as described in CVE-2025-27014, allows an attacker to inject malicious scripts into a web page, which are then executed in the user's browser.
As of the latest data, CVE-2025-27014 may potentially be exploited by attackers, highlighting the need for prompt remediation.