CVE-2025-31428: WordPress HYDRO theme <= 2.8 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddhaThemes HYDRO allows Reflected XSS. This issue affects HYDRO: from n/a through 2.8.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddhaThemes HYDRO hydro allows Reflected XSS.This issue affects HYDRO: from n/a through <= 2.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31428?
CVE-2025-31428 is categorized as a reflected cross-site scripting (XSS) vulnerability which can lead to unauthorized actions on behalf of users.
How do I fix CVE-2025-31428?
To fix CVE-2025-31428, update to version 2.9 or higher of the BuddhaThemes HYDRO theme, which resolves the vulnerability.
Which versions of BuddhaThemes HYDRO are affected by CVE-2025-31428?
CVE-2025-31428 affects all versions of BuddhaThemes HYDRO up to and including version 2.8.
What types of attacks can be executed due to CVE-2025-31428?
CVE-2025-31428 allows attackers to execute malicious scripts in the context of a user's browser session, potentially leading to data theft or manipulation.
Is CVE-2025-31428 specific to a particular platform?
Yes, CVE-2025-31428 specifically affects the BuddhaThemes HYDRO theme used in WordPress.