CVE-2025-64202: WordPress Sahifa theme < 5.8.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Sahifa sahifa allows DOM-Based XSS.This issue affects Sahifa: from n/a through < 5.8.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64202?
CVE-2025-64202 has been classified as a high severity vulnerability due to its potential for exploitation through DOM-Based XSS.
How do I fix CVE-2025-64202?
To mitigate CVE-2025-64202, update TieLabs Sahifa to the latest version, specifically version 5.8.6 or higher.
What types of attacks are possible due to CVE-2025-64202?
CVE-2025-64202 allows attackers to execute scripts in the context of the user's browser, leading to possible data theft or session hijacking.
Which versions of Sahifa are affected by CVE-2025-64202?
CVE-2025-64202 affects Sahifa versions prior to 5.8.6.
Is my website at risk if I use an outdated version of Sahifa?
Yes, if you are using an outdated version of Sahifa below 5.8.6, your website is at risk for exploitation through CVE-2025-64202.