CVE-2025-49046: WordPress xPromoter plugin <= 1.3.4 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jan 22, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup xPromoter topbarpromoter allows Reflected XSS.This issue affects xPromoter: from n/a through <= 1.3.4.
Affected Software
2 affected components
LambertGroup xPromoter<=1.3.4
wordpress/xpromoter<=1.3.4
Event History
Jan 22, 2026
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Oct 12, 58279
Event
via MITRE·09:36 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-49046?
CVE-2025-49046 has a moderate severity level due to its potential to allow reflected XSS attacks.
2
How do I fix CVE-2025-49046?
To fix CVE-2025-49046, update the xPromoter plugin to version 1.3.5 or later.
3
What types of attacks can CVE-2025-49046 facilitate?
CVE-2025-49046 can facilitate reflected cross-site scripting (XSS) attacks, allowing malicious scripts to be executed in users' browsers.
4
Which versions of the xPromoter plugin are affected by CVE-2025-49046?
CVE-2025-49046 affects all versions of the xPromoter plugin up to and including version 1.3.4.
5
Who is the vendor of the vulnerable product related to CVE-2025-49046?
The vendor of the vulnerable product is LambertGroup, which develops the xPromoter plugin.