First published: Thu Apr 03 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Header and Footer allows Stored XSS. This issue affects CM Header and Footer: from n/a through 1.2.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress CM Header and Footer | <=1.2.4 | |
WordPress CM Header and Footer | <=1.2.4 |
Update the WordPress CM Header and Footer plugin to the latest available version (at least 1.2.5).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31091 has a high severity rating due to the potential for Stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-31091, upgrade the CM Header and Footer plugin to version 1.2.5 or later, which addresses the vulnerability.
CVE-2025-31091 affects the CM Header and Footer plugin versions from n/a up to 1.2.4.
CVE-2025-31091 may allow attackers to execute arbitrary JavaScript in a victim's browser session, leading to unauthorized actions or data theft.
The best workaround for CVE-2025-31091 is to disable the CM Header and Footer plugin until it can be updated.