First published: Mon Mar 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tstafford include-file allows Stored XSS. This issue affects include-file: from n/a through 1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
tstafford include-file | <=1 | |
WordPress | <=1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30595 has a high severity rating due to its potential for Stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-30595, update the tstafford include-file and WordPress include-file to the latest version beyond 1.
CVE-2025-30595 affects users of the tstafford include-file and WordPress include-file up to version 1.
Stored XSS in CVE-2025-30595 allows an attacker to inject malicious scripts that are permanently stored on the server and executed when users access the affected web page.
If unable to update, consider disabling the vulnerable plugin until a security patch is available.