CVE-2025-54698: WordPress Classified Listing Plugin plugin <= 5.0.0 - Content Injection Vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RadiusTheme Classified Listing allows Code Injection. This issue affects Classified Listing: from n/a through 5.0.0.
Other sources
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RadiusTheme Classified Listing classified-listing allows Code Injection.This issue affects Classified Listing: from n/a through <= 5.0.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54698?
CVE-2025-54698 is classified as a moderate severity vulnerability due to its potential for code injection via improper neutralization of script-related HTML tags.
How do I fix CVE-2025-54698?
To fix CVE-2025-54698, you should update the RadiusTheme Classified Listing or WordPress Classified Listing Plugin to a version beyond 5.0.0 that addresses this vulnerability.
What systems are affected by CVE-2025-54698?
CVE-2025-54698 affects RadiusTheme Classified Listing versions up to 5.0.0 and WordPress Classified Listing Plugin versions up to 5.0.0.
What type of vulnerability is CVE-2025-54698?
CVE-2025-54698 is categorized as a Basic XSS vulnerability, allowing for code injection through improperly neutralized HTML tags.
What are the potential risks of CVE-2025-54698?
The potential risks of CVE-2025-54698 include unauthorized access to user data and execution of malicious scripts on affected systems.