CVE-2025-64194: WordPress Eduma theme <= 5.7.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma eduma allows Stored XSS.This issue affects Eduma: from n/a through <= 5.7.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64194?
CVE-2025-64194 has been classified as a high-severity vulnerability due to its potential for stored Cross-site Scripting (XSS).
How do I fix CVE-2025-64194?
To fix CVE-2025-64194, you should update ThimPress Eduma to the latest version beyond 5.7.6 to eliminate the stored XSS vulnerability.
What types of attacks can CVE-2025-64194 enable?
CVE-2025-64194 can enable attackers to execute malicious scripts in the context of the user's browser session, potentially leading to data theft and information compromise.
Which versions of Eduma are affected by CVE-2025-64194?
CVE-2025-64194 affects all versions of Eduma from n/a through 5.7.6.
Who is impacted by CVE-2025-64194?
Users running ThimPress Eduma version 5.7.6 or earlier are vulnerable to CVE-2025-64194 and should take immediate action to update.