CVE-2025-31907: WordPress Team Builder plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Team Builder team-display allows Reflected XSS.This issue affects Team Builder: from n/a through <= 1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31907?
CVE-2025-31907 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-31907?
To fix CVE-2025-31907, update Labib Ahmed Team Builder or the WordPress Team Builder plugin to versions beyond 1.3.
Who is affected by CVE-2025-31907?
CVE-2025-31907 affects users of Labib Ahmed Team Builder and the WordPress Team Builder plugin up to version 1.3.
What type of vulnerability is CVE-2025-31907?
CVE-2025-31907 is categorized as an improper neutralization of input during web page generation, specifically allowing reflected cross-site scripting.
Can CVE-2025-31907 lead to data theft?
Yes, CVE-2025-31907 can potentially allow attackers to execute scripts in the user's browser, leading to data theft.