First published: Tue Apr 22 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms allows Stored XSS. This issue affects HTML Forms: from n/a through 1.5.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Link Software LLC HTML Forms | <=1.5.2 | |
WordPress HTML Forms | <=1.5.2 | |
Ibericode Html Forms | <1.5.3 |
Update the WordPress HTML Forms plugin to the latest available version (at least 1.5.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46236 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS).
To fix CVE-2025-46236, upgrade Link Software LLC HTML Forms to version 1.5.3 or later, or ensure that input sanitization measures are implemented.
The impact of CVE-2025-46236 includes possible unauthorized access and manipulation of user data through stored XSS attacks.
Users of Link Software LLC HTML Forms and WordPress HTML Forms versions up to and including 1.5.2 are affected by CVE-2025-46236.
Yes, CVE-2025-46236 is remotely exploitable, allowing attackers to execute scripts in the context of a user's session.