CVE-2025-39585: WordPress Travelfic Toolkit plugin <= 1.2.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Travelfic Toolkit allows Stored XSS. This issue affects Travelfic Toolkit: from n/a through 1.2.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Travelfic Toolkit travelfic-toolkit allows Stored XSS.This issue affects Travelfic Toolkit: from n/a through <= 1.2.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39585?
CVE-2025-39585 is classified as a high severity vulnerability due to its potential for allowing stored cross-site scripting (XSS).
How do I fix CVE-2025-39585?
To fix CVE-2025-39585, you should update the Travelfic Toolkit to version 1.2.2 or later, which addresses the vulnerability.
What type of vulnerability is CVE-2025-39585?
CVE-2025-39585 is an improper neutralization of input during web page generation, leading to a stored XSS vulnerability.
Which versions of the Travelfic Toolkit are affected by CVE-2025-39585?
CVE-2025-39585 affects all versions of the Travelfic Toolkit up to and including version 1.2.1.
Who is impacted by CVE-2025-39585?
Users of the Travelfic Toolkit on WordPress running versions up to 1.2.1 are impacted by CVE-2025-39585.