CVE-2025-63057: WordPress Wp Ultimate Review plugin <= 2.3.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows DOM-Based XSS.This issue affects Wp Ultimate Review: from n/a through <= 2.3.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63057?
CVE-2025-63057 is considered a high-severity vulnerability due to its potential for exploiting Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-63057?
To fix CVE-2025-63057, update the Wp Ultimate Review plugin to the latest version beyond 2.3.6.
What type of vulnerability is CVE-2025-63057?
CVE-2025-63057 is a Cross-site Scripting (XSS) vulnerability occurring due to improper input neutralization in webpage generation.
Which versions of Wp Ultimate Review are affected by CVE-2025-63057?
CVE-2025-63057 affects Wp Ultimate Review versions up to and including 2.3.6.
Can CVE-2025-63057 be exploited remotely?
Yes, CVE-2025-63057 can potentially be exploited remotely, allowing attackers to perform actions in the context of another user.