CVE-2025-31892: WordPress WP Crowdfunding plugin <= 2.1.15 - Cross Site Scripting (XSS) vulnerability
Published Apr 1, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding wp-crowdfunding allows Stored XSS.This issue affects WP Crowdfunding: from n/a through <= 2.1.15.
Affected Software
1 affected component
Themeum WP Crowdfunding<=2.1.15
Event History
Apr 1, 2025
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-31892?
CVE-2025-31892 is classified as a high-severity vulnerability due to its potential for Stored Cross-site Scripting (XSS) attacks.
2
How do I fix CVE-2025-31892?
To fix CVE-2025-31892, update WP Crowdfunding to version 2.1.14 or later.
3
What kind of vulnerability is CVE-2025-31892?
CVE-2025-31892 is a Stored Cross-site Scripting (XSS) vulnerability affecting WP Crowdfunding.
4
Which versions of WP Crowdfunding are affected by CVE-2025-31892?
CVE-2025-31892 affects WP Crowdfunding versions up to and including 2.1.13.
5
What impact does CVE-2025-31892 have on users?
The impact of CVE-2025-31892 allows attackers to inject malicious scripts into web pages viewed by other users, potentially compromising their data.