CVE-2025-48252: WordPress Back Button Widget plugin <= 1.6.8 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget back-button-widget allows Stored XSS.This issue affects Back Button Widget: from n/a through <= 1.6.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48252?
The severity of CVE-2025-48252 is classified as medium due to its capability to allow stored cross-site scripting attacks.
How do I fix CVE-2025-48252?
To fix CVE-2025-48252, update the WPFactory Back Button Widget to version 1.6.9 or later.
What are the potential impacts of CVE-2025-48252?
CVE-2025-48252 can allow attackers to execute arbitrary JavaScript in the context of the user's browser, leading to data theft or account compromise.
Which versions are affected by CVE-2025-48252?
CVE-2025-48252 affects all versions of the WPFactory Back Button Widget from the initial release up to and including version 1.6.8.
Who is responsible for fixing CVE-2025-48252?
The responsibility for addressing CVE-2025-48252 lies with the maintainers of the WPFactory Back Button Widget.