CVE-2025-48296: WordPress UpStore <= 1.7.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup UpStore allows Reflected XSS. This issue affects UpStore: from n/a through 1.7.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup UpStore upstore allows Reflected XSS.This issue affects UpStore: from n/a through <= 1.7.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48296?
CVE-2025-48296 is classified as a reflected cross-site scripting (XSS) vulnerability, which poses a significant risk to user data and web application integrity.
How do I fix CVE-2025-48296?
To mitigate CVE-2025-48296, upgrade UpStore to the latest version beyond 1.7.0 where the vulnerability has been patched.
Which versions of UpStore are affected by CVE-2025-48296?
CVE-2025-48296 affects all versions of UpStore from the beginning up to and including version 1.7.0.
Can CVE-2025-48296 be exploited remotely?
Yes, CVE-2025-48296 can be exploited remotely through manipulated web requests by an attacker.
What are the potential impacts of CVE-2025-48296?
Exploitation of CVE-2025-48296 can lead to unauthorized actions within user sessions, potentially compromising sensitive information.