First published: Thu Apr 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Silver Muru WS Force Login Page allows Stored XSS. This issue affects WS Force Login Page: from n/a through 3.0.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WS Force Login Page | <=3.0.3 | |
WordPress WS Force Login Page | <=3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-46521 is considered high due to the potential for stored cross-site scripting (XSS) attacks.
To fix CVE-2025-46521, upgrade the WS Force Login Page plugin to version 3.0.4 or later.
CVE-2025-46521 is a cross-site scripting (XSS) vulnerability resulting from improper input neutralization.
CVE-2025-46521 affects the Silver Muru WS Force Login Page plugin versions up to and including 3.0.3.
Exploitation of CVE-2025-46521 could lead to unauthorized actions being performed on behalf of users or sensitive information being stolen.