CVE-2025-53307: WordPress Assistant Plugin <= 1.5.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from n/a through <= 1.5.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brent Jett Assistant allows Reflected XSS. This issue affects Assistant: from n/a through 1.5.2.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53307?
The severity of CVE-2025-53307 is considered to be moderate due to the potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-53307?
To fix CVE-2025-53307, update Brent Jett Assistant or WordPress Assistant Plugin to version 1.5.3 or later.
What applications are affected by CVE-2025-53307?
CVE-2025-53307 affects Brent Jett Assistant versions up to and including 1.5.2 and the WordPress Assistant Plugin versions up to and including 1.5.2.
What type of vulnerability is CVE-2025-53307?
CVE-2025-53307 is classified as a cross-site scripting (XSS) vulnerability due to improper input neutralization during web page generation.
Can CVE-2025-53307 be exploited remotely?
Yes, CVE-2025-53307 can be exploited remotely, allowing attackers to inject malicious scripts into the web pages viewed by users.