CVE-2025-57926: WordPress Passster Plugin <= 4.2.18 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster allows Stored XSS. This issue affects Passster: from n/a through 4.2.18.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster content-protector allows Stored XSS.This issue affects Passster: from n/a through <= 4.2.18.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57926?
CVE-2025-57926 has a severity rating indicating a high risk due to stored cross-site scripting vulnerabilities.
How do I fix CVE-2025-57926?
To fix CVE-2025-57926, update the WP Chill Passster plugin to version 4.2.19 or later.
What types of attacks can CVE-2025-57926 allow?
CVE-2025-57926 can allow attackers to execute malicious scripts in the context of a user's browser, potentially compromising user data.
Who is affected by CVE-2025-57926?
CVE-2025-57926 affects users of the WP Chill Passster plugin versions up to 4.2.18.
What is the CVSS score for CVE-2025-57926?
The CVSS score for CVE-2025-57926 reflects a high level of severity, making it crucial for users to apply necessary patches.