CVE-2025-36548: XSS
A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36548?
CVE-2025-36548 is considered a high severity cross-site scripting vulnerability.
How do I fix CVE-2025-36548?
To fix CVE-2025-36548, update to the latest version of WWBN AVideo that addresses this vulnerability.
What type of attack is associated with CVE-2025-36548?
CVE-2025-36548 is associated with cross-site scripting attacks that allow arbitrary JavaScript execution.
What versions of WWBN AVideo are affected by CVE-2025-36548?
CVE-2025-36548 affects WWBN AVideo version 14.4 and the dev master commit 8a8954ff.
What is the impact of CVE-2025-36548 on users?
The impact of CVE-2025-36548 allows attackers to execute arbitrary JavaScript in the context of the affected user's session.