First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in divspark Flagged Content allows Reflected XSS. This issue affects Flagged Content: from n/a through 1.0.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Flagged Content Plugin | <=1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27284 has been classified as a critical vulnerability due to its potential for reflected cross-site scripting attacks.
To fix CVE-2025-27284, update the WordPress Flagged Content Plugin to version 1.0.3 or higher.
CVE-2025-27284 affects the WordPress Flagged Content Plugin version 1.0.2 and earlier.
CVE-2025-27284 is associated with reflected cross-site scripting (XSS) attacks.
Yes, CVE-2025-27284 can be exploited remotely through maliciously crafted URLs that leverage the vulnerability.