First published: Fri Apr 04 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in noonnoo Gravel allows Reflected XSS.This issue affects Gravel: from n/a through 1.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31418 is classified as a high severity vulnerability due to the potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-31418, update the Gravel theme to the latest version beyond 1.6 to mitigate the reflected XSS vulnerability.
The risks associated with CVE-2025-31418 include the possibility of attackers executing malicious scripts in the context of the user's browser.
CVE-2025-31418 affects all versions of the Gravel theme up to and including version 1.6.
CVE-2025-31418 can compromise website security by allowing attackers to conduct phishing attacks or steal sensitive user information through XSS.