CVE-2025-31409: WordPress Bridge Core plugin < 3.3.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core allows Stored XSS. This issue affects Bridge Core: from n/a through n/a.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core bridge-core allows Stored XSS.This issue affects Bridge Core: from n/a through < 3.3.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31409?
CVE-2025-31409 is rated as a high severity vulnerability due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-31409?
To mitigate CVE-2025-31409, update the Bridge Core plugin to version 3.3.2 or later, as it includes security patches addressing this vulnerability.
What can attackers do with CVE-2025-31409?
Attackers can exploit CVE-2025-31409 to inject malicious scripts that execute in the context of users' browsers, potentially stealing sensitive information.
Which versions of Bridge Core are affected by CVE-2025-31409?
CVE-2025-31409 affects all versions of Bridge Core prior to 3.3.2.
Is user input involved in CVE-2025-31409?
Yes, CVE-2025-31409 involves improper neutralization of user input during web page generation, which allows for stored cross-site scripting.