CVE-2025-47501: WordPress Content Control plugin <= 2.6.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Code Atlantic Content Control allows DOM-Based XSS. This issue affects Content Control: from n/a through 2.6.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Iser Content Control content-control allows DOM-Based XSS.This issue affects Content Control: from n/a through <= 2.6.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47501?
CVE-2025-47501 has a medium severity rating due to its potential for DOM-Based Cross-site Scripting (XSS) attacks.
How can I mitigate CVE-2025-47501?
To fix CVE-2025-47501, update Code Atlantic Content Control to version 2.6.2 or later.
What versions are affected by CVE-2025-47501?
CVE-2025-47501 affects all versions of Code Atlantic Content Control up to and including 2.6.1.
What types of attacks can CVE-2025-47501 enable?
CVE-2025-47501 enables attackers to perform DOM-Based Cross-site Scripting (XSS) attacks.
Who is impacted by CVE-2025-47501?
Users of Code Atlantic Content Control and WordPress Content Control versions up to 2.6.1 are impacted by CVE-2025-47501.