CVE-2025-63045: WordPress Master Slider Pro plugin <= 3.7.12 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in averta Master Slider Pro masterslider allows DOM-Based XSS.This issue affects Master Slider Pro: from n/a through <= 3.7.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63045?
CVE-2025-63045 is classified as a high severity vulnerability due to its potential for DOM-Based Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-63045?
To fix CVE-2025-63045, update the Averta Master Slider Pro plugin to version 3.7.13 or later.
What versions are affected by CVE-2025-63045?
CVE-2025-63045 affects all versions of Averta Master Slider Pro from n/a through 3.7.12.
What type of vulnerability is CVE-2025-63045?
CVE-2025-63045 is an improper neutralization of input during web page generation vulnerability, commonly referred to as Cross-site Scripting (XSS).
Is my website at risk if I use Master Slider Pro version 3.7.12?
Yes, if you are using Master Slider Pro version 3.7.12 or earlier, your website is at risk of exploitation through CVE-2025-63045.