CVE-2025-48162: WordPress Simple Business Directory Pro <= 15.5.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro allows Reflected XSS. This issue affects Simple Business Directory Pro: from n/a through 15.5.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Reflected XSS.This issue affects Simple Business Directory Pro: from n/a through <= 15.5.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48162?
CVE-2025-48162 has a medium severity rating due to its potential impact on user data through reflected cross-site scripting.
How do I fix CVE-2025-48162?
To fix CVE-2025-48162, update Simple Business Directory Pro to the latest version that is above 15.5.1.
What is the impact of CVE-2025-48162 on users?
The impact of CVE-2025-48162 includes the potential for attackers to execute malicious scripts on behalf of users, compromising data security.
Is CVE-2025-48162 still a threat if I'm using a later version than 15.5.1?
No, if you are using a version later than 15.5.1, CVE-2025-48162 is not a threat to your application.
Who is affected by CVE-2025-48162?
CVE-2025-48162 affects users of QuantumCloud Simple Business Directory Pro and WordPress Simple Business Directory Pro versions up to and including 15.5.1.