CVE-2025-62982: WordPress Dynamic User Directory plugin <= 2.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarah Giles Dynamic User Directory dynamic-user-directory allows Stored XSS.This issue affects Dynamic User Directory: from n/a through <= 2.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62982?
CVE-2025-62982 has a medium severity rating due to the risk of stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-62982?
To fix CVE-2025-62982, upgrade the Dynamic User Directory plugin to a version greater than 2.3.
What software is affected by CVE-2025-62982?
CVE-2025-62982 affects the Dynamic User Directory plugin versions up to and including 2.3.
Can CVE-2025-62982 be exploited remotely?
Yes, CVE-2025-62982 can be exploited remotely by attackers using crafted input to inject malicious scripts.
What are the potential impacts of CVE-2025-62982?
The potential impacts of CVE-2025-62982 include unauthorized access to user data and the execution of arbitrary scripts in the context of the affected site.