CVE-2025-49322: WordPress 404 Page by SeedProd plugin < 1.0.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeedProd 404 Page by SeedProd 404-page allows Stored XSS.This issue affects 404 Page by SeedProd: from n/a through < 1.0.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeedProd 404 Page by SeedProd allows Stored XSS. This issue affects 404 Page by SeedProd: from n/a through n/a.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49322?
CVE-2025-49322 is classified as a Stored XSS vulnerability which can be exploited to execute malicious scripts.
How do I fix CVE-2025-49322?
To mitigate CVE-2025-49322, update the SeedProd 404 Page plugin to version 1.0.3 or later.
What software is affected by CVE-2025-49322?
CVE-2025-49322 affects versions of SeedProd 404 Page by SeedProd up to and including version 1.0.2.
What type of vulnerability is CVE-2025-49322?
CVE-2025-49322 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as Cross-site Scripting (XSS).
Is CVE-2025-49322 a critical vulnerability?
While CSRF vulnerabilities can vary in impact, CVE-2025-49322's potential for Stored XSS makes it a significant security concern.