First published: Thu Apr 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DanielRiera Image Style Hover allows DOM-Based XSS. This issue affects Image Style Hover: from n/a through 1.0.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
DanielRiera Image Style Hover | <=1.0.6 | |
WordPress Image Style Hover | <=1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46534 is classified as a high-severity vulnerability due to its potential for enabling DOM-Based XSS attacks.
To fix CVE-2025-46534, update the DanielRiera Image Style Hover plugin to version 1.0.7 or later.
CVE-2025-46534 affects DanielRiera Image Style Hover versions up to and including 1.0.6.
CVE-2025-46534 allows attackers to exploit DOM-Based XSS vulnerabilities which can lead to unauthorized actions on behalf of users.
Yes, CVE-2025-46534 also affects the WordPress Image Style Hover plugin up to version 1.0.6.