First published: Wed May 07 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Seb WP DPE-GES allows DOM-Based XSS. This issue affects WP DPE-GES: from n/a through 1.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=1.6 |
Update the WordPress WP DPE-GES plugin to the latest available version (at least 1.7).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47515 is classified as a medium-severity vulnerability due to its potential for Cross-site Scripting (XSS) attacks.
To mitigate CVE-2025-47515, update the WP DPE-GES plugin to version 1.7 or later.
CVE-2025-47515 is caused by improper neutralization of user input during web page generation that allows for DOM-Based XSS.
CVE-2025-47515 affects all versions of WP DPE-GES from release until version 1.6.
Exploitation of CVE-2025-47515 can lead to unauthorized script execution in the context of a user's browser, potentially compromising their data.