CVE-2025-64208: WordPress Jannah - Extensions plugin <= 1.1.4 - Cross Site Scripting (XSS) vulnerability
Published Oct 29, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Jannah - Extensions jannah-extensions allows DOM-Based XSS.This issue affects Jannah - Extensions: from n/a through <= 1.1.4.
Affected Software
2 affected components
Tielabs Jannah - Extensions<=1.1.4
WordPress Jannah - Extensions<=1.1.4
Event History
Oct 29, 2025
CVE Published
via MITRE·08:38 AM
Data Sourced
via MITRE·08:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-64208?
CVE-2025-64208 has a high severity rating due to the potential for exploitation through Cross-site Scripting (XSS).
2
How do I fix CVE-2025-64208?
To fix CVE-2025-64208, update the Jannah - Extensions to version 1.1.5 or later.
3
What versions are affected by CVE-2025-64208?
CVE-2025-64208 affects Jannah - Extensions versions up to and including 1.1.4.
4
What type of vulnerability is CVE-2025-64208?
CVE-2025-64208 is classified as a Cross-site Scripting (XSS) vulnerability.
5
Who is the vendor of the affected software for CVE-2025-64208?
The vendor of the affected software for CVE-2025-64208 is TieLabs.