First published: Thu Apr 10 2025(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Stored XSS. This issue affects Accessibility Suite by Online ADA: from n/a through 4.18.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ability, Inc Accessibility Suite | <=4.18 | |
WordPress Accessibility Suite | <=4.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32215 has been classified with a medium severity due to its ability to allow stored XSS via unrestricted file uploads.
To fix CVE-2025-32215, update Accessibility Suite by Online ADA to version 4.19 or later, or apply any security patches provided by the vendor.
CVE-2025-32215 affects the Ability, Inc Accessibility Suite and the WordPress Accessibility Suite plugin, both up to version 4.18.
CVE-2025-32215 is categorized as an unrestricted file upload vulnerability that can lead to stored cross-site scripting (XSS).
Yes, CVE-2025-32215 can be exploited remotely by uploading malicious files that trigger stored XSS upon access.