First published: Tue Mar 11 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Sharma wordpress login form to anywhere allows Stored XSS. This issue affects wordpress login form to anywhere: from n/a through 0.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28914 is a medium severity vulnerability due to its potential to allow stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-28914, update the 'WordPress login form to anywhere' plugin to the latest version or apply necessary patches provided by the vendor.
CVE-2025-28914 affects users of the 'WordPress login form to anywhere' plugin, specifically versions up to 0.2.
CVE-2025-28914 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
The implications of CVE-2025-28914 include the possibility of attackers executing malicious scripts in the context of authenticated users, leading to potential data theft or site compromise.