CVE-2025-39497: WordPress Dokan Pro plugin <= 3.14.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro allows Stored XSS.This issue affects Dokan Pro: from n/a through 3.14.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro dokan-pro allows Stored XSS.This issue affects Dokan Pro: from n/a through <= 3.14.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39497?
CVE-2025-39497 is classified as a high severity vulnerability due to its potential to allow stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-39497?
To fix CVE-2025-39497, upgrade Dokan Pro to version 3.14.6 or later, where the vulnerability has been patched.
What are the potential impacts of CVE-2025-39497?
If exploited, CVE-2025-39497 could allow attackers to execute arbitrary JavaScript in the context of a user's browser session, potentially leading to data theft or account compromise.
Who is affected by CVE-2025-39497?
CVE-2025-39497 affects users of Dokan Pro versions up to and including 3.14.5.
What type of vulnerability is CVE-2025-39497?
CVE-2025-39497 is a Cross-site Scripting (XSS) vulnerability characterized by improper neutralization of input during web page generation.