CVE-2025-57911: WordPress Adverts Plugin <= 1.4 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Adverts adverts-click-tracker allows DOM-Based XSS.This issue affects Adverts: from n/a through <= 1.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Adverts allows DOM-Based XSS. This issue affects Adverts: from n/a through 1.4.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57911?
CVE-2025-57911 is classified as a medium severity vulnerability due to its potential to exploit DOM-based cross-site scripting (XSS).
How do I fix CVE-2025-57911?
To fix CVE-2025-57911, update the WPFactory Adverts plugin to version 1.4 or higher, as earlier versions are vulnerable to XSS issues.
What software is affected by CVE-2025-57911?
CVE-2025-57911 affects the WPFactory Adverts plugin in versions up to and including 1.4.
Can CVE-2025-57911 impact websites using WordPress?
Yes, CVE-2025-57911 can impact any WordPress website using the vulnerable version of the WPFactory Adverts plugin.
What type of vulnerability is CVE-2025-57911?
CVE-2025-57911 is an improper neutralization of input vulnerability, resulting in a cross-site scripting (XSS) attack.