First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpion Live css allows Stored XSS. This issue affects Live css: from n/a through 1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Live CSS | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27295 has a medium severity rating due to its potential for Stored Cross-Site Scripting attacks.
To fix CVE-2025-27295, upgrade the WordPress Live CSS plugin to a version later than 1.3.
CVE-2025-27295 affects the WordPress Live CSS plugin versions from n/a to 1.3.
CVE-2025-27295 is an improper neutralization of input vulnerability that allows Stored Cross-Site Scripting.
Yes, CVE-2025-27295 can be exploited by an attacker to execute malicious scripts in the context of an affected user's browser.