First published: Tue Apr 01 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weblizar About Author allows Reflected XSS. This issue affects About Author: from n/a through 1.6.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Weblizar | <=1.6.2 | |
WordPress About Author plugin | <=1.6.2 |
Update the WordPress About Author plugin to the latest available version (at least 1.6.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30808 is classified as a critical severity vulnerability due to its ability to allow reflected Cross-site Scripting (XSS).
To fix CVE-2025-30808, update the WebLizar About Author plugin to version 1.6.3 or later to mitigate the XSS vulnerability.
CVE-2025-30808 affects versions up to and including 1.6.2 of the WebLizar About Author plugin.
CVE-2025-30808 is a reflected Cross-site Scripting (XSS) vulnerability, which allows attackers to inject malicious scripts.
Yes, the About Author plugin for WordPress is affected by CVE-2025-30808 if it is version 1.6.2 or earlier.