CVE-2025-31072: WordPress Ofiz - Business Consulting Theme plugin <= 2.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Ofiz - WordPress Business Consulting Theme allows Reflected XSS. This issue affects Ofiz - WordPress Business Consulting Theme: from n/a through 2.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Ofiz - WordPress Business Consulting Theme ofiz allows Reflected XSS.This issue affects Ofiz - WordPress Business Consulting Theme: from n/a through <= 2.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31072?
CVE-2025-31072 is classified as a Cross-site Scripting (XSS) vulnerability, which can lead to unwanted code execution in a user's browser.
How do I fix CVE-2025-31072?
To fix CVE-2025-31072, it is recommended to update the Ofiz - WordPress Business Consulting Theme to version 2.1 or above.
What impact does CVE-2025-31072 have on users?
CVE-2025-31072 could allow attackers to execute scripts in users' browsers, potentially compromising user data and session information.
Which versions of the Ofiz theme are affected by CVE-2025-31072?
CVE-2025-31072 affects the Ofiz - WordPress Business Consulting Theme versions up to and including 2.0.
Is CVE-2025-31072 exploitable remotely?
Yes, CVE-2025-31072 is a reflected XSS vulnerability, making it exploitable remotely by an attacker.