CVE-2025-32548: WordPress Hamburger Icon Menu Lite Plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in borisolhor Hamburger Icon Menu Lite allows Reflected XSS. This issue affects Hamburger Icon Menu Lite: from n/a through 1.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in borisolhor Hamburger Icon Menu Lite hamburger-icon-menu-lite allows Reflected XSS.This issue affects Hamburger Icon Menu Lite: from n/a through <= 1.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32548?
CVE-2025-32548 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting.
How do I fix CVE-2025-32548?
To mitigate CVE-2025-32548, update the Borisolhor Hamburger Icon Menu Lite to a version higher than 1.0, if available.
Which versions are affected by CVE-2025-32548?
CVE-2025-32548 affects Borisolhor Hamburger Icon Menu Lite versions up to and including 1.0.
What type of vulnerability is CVE-2025-32548?
CVE-2025-32548 is an improper neutralization of input during web page generation, leading to reflected cross-site scripting (XSS).
Is CVE-2025-32548 specific to any platform?
CVE-2025-32548 primarily affects the Borisolhor Hamburger Icon Menu Lite and the WordPress Hamburger Icon Menu Lite Plugin.