CVE-2025-53278: WordPress WP AdCenter plugin <= 2.6.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter allows Stored XSS. This issue affects WP AdCenter: from n/a through 2.6.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter: from n/a through <= 2.6.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53278?
The severity of CVE-2025-53278 is considered high due to its ability to allow Stored Cross-site Scripting (XSS) vulnerabilities.
How do I fix CVE-2025-53278?
To fix CVE-2025-53278, update the WPeka WP AdCenter plugin to version 2.6.1 or higher as it addresses the vulnerability.
What systems are affected by CVE-2025-53278?
CVE-2025-53278 affects all versions of WPeka WP AdCenter up to and including version 2.6.0.
What type of vulnerability is CVE-2025-53278?
CVE-2025-53278 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
Can CVE-2025-53278 be exploited remotely?
Yes, CVE-2025-53278 can be exploited remotely, allowing attackers to inject malicious scripts into web pages viewed by users.