CVE-2025-28905: WordPress Featured Posts Grid plugin <= 1.7 - CSRF to Stored XSS vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chaser324 Featured Posts Grid featured-posts-grid allows Stored XSS.This issue affects Featured Posts Grid: from n/a through <= 1.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28905?
CVE-2025-28905 is classified as a medium-severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-28905?
To fix CVE-2025-28905, update the Chaser324 Featured Posts Grid plugin to the latest version that addresses this vulnerability.
What systems are affected by CVE-2025-28905?
CVE-2025-28905 affects versions of the Chaser324 Featured Posts Grid plugin from n/a to 1.7, including any installations on WordPress.
What types of attacks can exploit CVE-2025-28905?
CVE-2025-28905 can be exploited to execute stored XSS attacks, allowing attackers to inject malicious scripts into web pages.
What should I do if I am using an affected version of the Chaser324 Featured Posts Grid?
If using an affected version, immediately update to a patched version of the Chaser324 Featured Posts Grid plugin to mitigate the risk.