CVE-2025-31028: WordPress WP Hide Categories plugin <= 1.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Huseyin Berberoglu WP Hide Categories wp-hide-categories allows Reflected XSS.This issue affects WP Hide Categories: from n/a through <= 1.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Hide Categories allows Reflected XSS. This issue affects WP Hide Categories: from n/a through 1.0.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31028?
CVE-2025-31028 has been classified as a high severity vulnerability due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-31028?
To fix CVE-2025-31028, update the WP Hide Categories plugin to the latest version where this vulnerability has been addressed.
What types of systems are affected by CVE-2025-31028?
CVE-2025-31028 affects WordPress installations using WP Hide Categories plugin versions prior to 1.0.
What is the impact of CVE-2025-31028?
The impact of CVE-2025-31028 includes the possibility for attackers to execute arbitrary scripts in the context of a user's browser.
How can I detect CVE-2025-31028 in my application?
You can detect CVE-2025-31028 by scanning your WordPress site for outdated versions of the WP Hide Categories plugin.