First published: Tue Apr 01 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition allows Reflected XSS. This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through 5.2.18.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Small Package Quotes Plugin | <=5.2.18 | |
WordPress Small Package Quotes Plugin | <=5.2.18 |
Update the WordPress Small Package Quotes – Worldwide Express Edition plugin to the latest available version (at least 5.2.19).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31078 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
To fix CVE-2025-31078, update the Small Package Quotes – Worldwide Express Edition plugin to the latest version beyond 5.2.18.
The potential impacts of CVE-2025-31078 include unauthorized access to user sessions and the ability to execute malicious scripts in user browsers.
Yes, CVE-2025-31078 affects versions of Small Package Quotes – Worldwide Express Edition from n/a through 5.2.18.
Users of the Small Package Quotes – Worldwide Express Edition plugin in WordPress up to version 5.2.18 are affected by CVE-2025-31078.