CVE-2025-52770: WordPress Hello Followers plugin <= 2.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Hello Followers hellofollowers allows Reflected XSS.This issue affects Hello Followers: from n/a through <= 2.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52770?
CVE-2025-52770 is classified as a high severity vulnerability due to its referral to XSS attacks which can lead to data theft.
How do I fix CVE-2025-52770?
To fix CVE-2025-52770, upgrade the Hello Followers plugin to a version greater than 2.5.
What applications are affected by CVE-2025-52770?
CVE-2025-52770 affects versions of the Hello Followers plugin for both appscreo and WordPress, up to and including version 2.5.
What type of vulnerability is CVE-2025-52770?
CVE-2025-52770 is a Cross-site Scripting (XSS) vulnerability that can allow attackers to inject scripts into web pages.
Can CVE-2025-52770 lead to serious consequences for users?
Yes, if exploited, CVE-2025-52770 can result in unauthorized actions being taken on behalf of users, such as credential theft and data exposure.