First published: Tue Apr 22 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics allows Stored XSS. This issue affects Textmetrics: from n/a through 3.6.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Israpil Textmetrics | >=n/a<=3.6.2 | |
WordPress Textmetrics | <=3.6.2 |
Update the WordPress Textmetrics plugin to the latest available version (at least 3.6.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46229 has a moderate severity level due to its potential for storing malicious scripts.
To fix CVE-2025-46229, update Israpil Textmetrics to version 3.6.3 or later.
CVE-2025-46229 affects Israpil Textmetrics versions from n/a through 3.6.2, including WordPress implementations.
The impact of CVE-2025-46229 allows attackers to execute stored cross-site scripting (XSS) attacks.
CVE-2025-46229 is considered widespread due to its presence in common versions of Textmetrics used in web applications.