First published: Tue Apr 01 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Post Custom Templates Lite allows Stored XSS. This issue affects Post Custom Templates Lite: from n/a through 1.14.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Post Custom Templates Lite | <=1.14 | |
OTWthemes Post Custom Templates Lite | <=1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31767 has a high severity level due to its potential to allow Stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-31767, update OTWthemes Post Custom Templates Lite to version 1.15 or later.
CVE-2025-31767 affects OTWthemes Post Custom Templates Lite versions up to and including 1.14.
Stored XSS in CVE-2025-31767 refers to a vulnerability that allows attackers to inject malicious scripts that get executed when users access affected pages.
Yes, if you are using OTWthemes Post Custom Templates Lite version 1.14 or earlier, your WordPress site is vulnerable to CVE-2025-31767.