CVE-2025-46500: WordPress Wordpress Auto Spinner plugin <= 3.26.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Wordpress Auto Spinner allows Reflected XSS. This issue affects Wordpress Auto Spinner: from n/a through 3.25.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Wordpress Auto Spinner wp-auto-spinner allows Reflected XSS.This issue affects Wordpress Auto Spinner: from n/a through <= 3.26.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46500?
CVE-2025-46500 is classified as a high severity reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-46500?
To fix CVE-2025-46500, update the Wordpress Auto Spinner plugin to version 3.25.1 or later.
What products are affected by CVE-2025-46500?
CVE-2025-46500 affects the ValvePress Wordpress Auto Spinner plugin versions up to and including 3.25.0.
What kind of vulnerability is CVE-2025-46500?
CVE-2025-46500 is an improper neutralization of input during web page generation, specifically a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2025-46500 be exploited by attackers?
Yes, CVE-2025-46500 can be exploited by attackers to execute arbitrary scripts in the context of the user's browser.