CVE-2025-30838: WordPress Cozy Blocks plugin <= 2.1.6 - Cross Site Scripting (XSS) vulnerability
Published Mar 27, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks cozy-addons allows Stored XSS.This issue affects Cozy Blocks: from n/a through <= 2.1.6.
Affected Software
1 affected component
CozyThemes Cozy Blocks<=2.1.6
Remediation
Information
Update the WordPress Cozy Blocks plugin to the latest available version (at least 2.1.7).
Event History
Mar 27, 2025
CVE Published
via MITRE·10:55 AM
Data Sourced
via MITRE·10:55 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-30838?
CVE-2025-30838 is categorized as a Stored Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-30838?
To fix CVE-2025-30838, upgrade Cozy Blocks to version 2.1.7 or later.
3
What versions are affected by CVE-2025-30838?
CVE-2025-30838 affects Cozy Blocks versions from n/a up to 2.1.6 inclusive.
4
What type of vulnerability is CVE-2025-30838?
CVE-2025-30838 is an improper neutralization of input during web page generation vulnerability.
5
Where is CVE-2025-30838 found?
CVE-2025-30838 is found in CozyThemes Cozy Blocks and the WordPress Cozy Blocks plugin.