First published: Fri Apr 25 2025(Updated: )
The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Custom Admin-Bar Favorites | <=0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3868 is classified as a high severity vulnerability due to the potential for reflected cross-site scripting attacks.
To fix CVE-2025-3868, update the Custom Admin-Bar Favorites plugin to a version above 0.1 that addresses the input sanitization issue.
CVE-2025-3868 affects all versions of the Custom Admin-Bar Favorites plugin for WordPress up to and including version 0.1.
Yes, CVE-2025-3868 can be exploited by unauthenticated attackers due to the lack of proper input validation.
CVE-2025-3868 allows for reflected cross-site scripting (XSS) attacks, which can lead to unauthorized actions and data exposure.