CVE-2025-28977: WordPress WP Pipes Plugin <= 1.4.3 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes allows Reflected XSS. This issue affects WP Pipes: from n/a through 1.4.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes wp-pipes allows Reflected XSS.This issue affects WP Pipes: from n/a through <= 1.4.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28977?
CVE-2025-28977 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-28977?
To fix CVE-2025-28977, upgrade the ThimPress WP Pipes plugin to the latest version beyond 1.4.3.
What type of vulnerability is CVE-2025-28977?
CVE-2025-28977 is an improper neutralization of input during web page generation vulnerability, specifically a reflected XSS issue.
Which versions of WP Pipes are affected by CVE-2025-28977?
CVE-2025-28977 affects versions of WP Pipes from its initial release up to and including version 1.4.3.
Who is affected by CVE-2025-28977?
Users of the ThimPress WP Pipes plugin who are on version 1.4.3 or earlier are susceptible to CVE-2025-28977.