CVE-2025-49309: WordPress HT Team Member plugin <= 1.1.7 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Team Member allows Stored XSS. This issue affects HT Team Member: from n/a through 1.1.7.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Team Member ht-team-member allows Stored XSS.This issue affects HT Team Member: from n/a through <= 1.1.7.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49309?
CVE-2025-49309 is classified as a high severity vulnerability due to its potential for exploitation via stored cross-site scripting (XSS).
How do I fix CVE-2025-49309?
To remediate CVE-2025-49309, update the HT Team Member plugin to version 1.1.8 or higher, which contains the necessary security patches.
What types of applications are affected by CVE-2025-49309?
CVE-2025-49309 affects the HT Plugins HT Team Member plugin and WordPress installations using versions up to 1.1.7.
What can an attacker do by exploiting CVE-2025-49309?
An attacker exploiting CVE-2025-49309 can execute arbitrary JavaScript in the context of the user’s session, leading to data theft or other malicious actions.
Is CVE-2025-49309 an urgent vulnerability to address?
Yes, CVE-2025-49309 is an urgent vulnerability to address due to its high risk of exploitation in live applications.