First published: Thu Apr 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StressFree Sites Business Contact Widget allows Stored XSS. This issue affects Business Contact Widget: from n/a through 2.7.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
StressFree Sites Business Contact Widget | <=2.7.0 | |
StressFree Sites Business Contact Widget | <=2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46529 is classified as a critical vulnerability due to its potential for stored cross-site scripting (XSS).
To fix CVE-2025-46529, update the Business Contact Widget to the latest version beyond 2.7.0 where the vulnerability is patched.
CVE-2025-46529 is an improper neutralization of input during web page generation, specifically allowing stored cross-site scripting (XSS).
CVE-2025-46529 affects the StressFree Sites Business Contact Widget and the WordPress Business Contact Widget versions up to 2.7.0.
The risks associated with CVE-2025-46529 include potential exploitation by attackers to inject malicious scripts, leading to unauthorized access and data leakage.