CVE-2025-54055: WordPress Druco <= 1.5.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Druco allows Reflected XSS. This issue affects Druco: from n/a through 1.5.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Druco druco allows Reflected XSS.This issue affects Druco: from n/a through <= 1.5.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54055?
CVE-2025-54055 has a medium severity rating due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-54055?
To mitigate CVE-2025-54055, upgrade your Skygroup Druco or WordPress Druco to version 1.5.3 or later.
What impact does CVE-2025-54055 have on affected systems?
CVE-2025-54055 allows attackers to execute arbitrary JavaScript in the context of the user's browser, potentially stealing sensitive information.
Which versions of Druco are affected by CVE-2025-54055?
CVE-2025-54055 affects all versions of Druco up to and including 1.5.2.
Is CVE-2025-54055 applicable to both Skygroup and WordPress Druco?
Yes, CVE-2025-54055 impacts both Skygroup Druco and WordPress Druco versions up to 1.5.2.