CVE-2025-27285: WordPress Easy Form by AYS Plugin <= 2.6.9 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Easy Form by AYS allows Reflected XSS. This issue affects Easy Form by AYS: from n/a through 2.6.9.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Easy Form easy-form allows Reflected XSS.This issue affects Easy Form: from n/a through <= 2.6.9.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27285?
CVE-2025-27285 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-27285?
To fix CVE-2025-27285, update AYS Easy Form or WordPress Easy Form Plugin to version 2.6.10 or later, which contains the necessary patches.
What types of software are affected by CVE-2025-27285?
CVE-2025-27285 affects AYS Easy Form versions up to and including 2.6.9 and the WordPress Easy Form Plugin versions up to and including 2.6.9.
What is the nature of the vulnerability CVE-2025-27285?
CVE-2025-27285 is an improper neutralization of input during web page generation that allows for reflected cross-site scripting (XSS) attacks.
Can CVE-2025-27285 allow attackers to steal user data?
Yes, an attacker exploiting CVE-2025-27285 could potentially steal sensitive user data by executing malicious scripts in the user's browser.