CVE-2025-62060: WordPress Tab Ultimate plugin <= 1.8 - Cross Site Scripting (XSS) vulnerability
Published Oct 22, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Tab Ultimate tabs-pro.This issue affects Tab Ultimate: from n/a through <= 1.8.
Affected Software
2 affected components
Themepoints Tab Ultimate<=1.8
WordPress Tab Ultimate plugin<=1.8
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62060?
CVE-2025-62060 is classified as a high severity Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-62060?
To fix CVE-2025-62060, upgrade Themepoints Tab Ultimate to version 1.9 or later.
3
What are the affected versions for CVE-2025-62060?
CVE-2025-62060 affects Themepoints Tab Ultimate versions up to and including 1.8.
4
What type of vulnerability is CVE-2025-62060?
CVE-2025-62060 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as XSS.
5
Who is affected by CVE-2025-62060?
Users of Themepoints Tab Ultimate plugin version 1.8 or earlier are affected by CVE-2025-62060.