CVE-2025-49946: WordPress Auto Login After Registration plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cynob IT Consultancy Auto Login After Registration auto-login-after-registration allows Reflected XSS.This issue affects Auto Login After Registration: from n/a through <= 1.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49946?
CVE-2025-49946 is classified as a critical vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-49946?
To fix CVE-2025-49946, update the Auto Login After Registration plugin to the latest version beyond 1.0.0.
What type of vulnerability is CVE-2025-49946?
CVE-2025-49946 is a cross-site scripting (XSS) vulnerability that allows attackers to execute malicious scripts in the context of the user's browser.
Who is affected by CVE-2025-49946?
CVE-2025-49946 affects users of the Auto Login After Registration plugin version 1.0.0 or lower on WordPress.
What can attackers achieve with CVE-2025-49946?
Attackers can leverage CVE-2025-49946 to steal user session information, perform phishing attacks, or execute arbitrary scripts within a user's browser.