CVE-2025-28253: XSS
Published Mar 27, 2025
·Updated
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
Affected Software
1 affected component
MainWP MainWP Dashboard
Event History
Mar 27, 2025
CVE Published
via MITRE·12:00 AM
Rejected
via MITRE·12:00 AM
Data Sourced
via NVD·11:15 PM
Description
Apr 7, 2025
Rejected
via MITRE·07:55 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-28253?
CVE-2025-28253 is classified as a Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-28253?
To fix CVE-2025-28253, ensure that all user inputs in the affected areas are properly sanitized before being rendered.
3
What are the affected versions for CVE-2025-28253?
CVE-2025-28253 affects MainWP Dashboard version 5.3.4.
4
What components are involved in CVE-2025-28253?
CVE-2025-28253 involves the class/class-mainwp-post-handler.php component in MainWP Dashboard.
5
Can CVE-2025-28253 be exploited by a remote attacker?
Yes, CVE-2025-28253 can be exploited by a remote attacker to execute arbitrary JavaScript in the context of the user's browser.