CVE-2025-31925: WordPress SHOUT plugin <= 3.5.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup SHOUT allows Reflected XSS. This issue affects SHOUT: from n/a through 3.5.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup SHOUT lbg-audio8-html5-radioads allows Reflected XSS.This issue affects SHOUT: from n/a through <= 3.5.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31925?
CVE-2025-31925 has a medium severity level due to its potential to allow reflected cross-site scripting attacks.
How do I fix CVE-2025-31925?
To fix CVE-2025-31925, update the LambertGroup SHOUT or WordPress SHOUT plugin to version 3.5.4 or later.
What systems are affected by CVE-2025-31925?
CVE-2025-31925 affects LambertGroup SHOUT versions up to and including 3.5.3 and the WordPress SHOUT plugin versions up to and including 3.5.3.
What type of vulnerability is CVE-2025-31925?
CVE-2025-31925 is classified as a Cross-site Scripting (XSS) vulnerability, specifically a reflected XSS.
Can CVE-2025-31925 lead to data theft?
Yes, if exploited, CVE-2025-31925 can allow attackers to execute malicious scripts in users' browsers, potentially leading to data theft.