CVE-2025-64217: WordPress Photography theme <= 7.7.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows Reflected XSS.This issue affects Photography: from n/a through <= 7.7.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64217?
CVE-2025-64217 is a medium severity vulnerability due to its capability to exploit reflected XSS in the ThemeGoods Photography plugin.
How do I fix CVE-2025-64217?
To fix CVE-2025-64217, upgrade the ThemeGoods Photography plugin to the latest version, specifically above 7.7.2.
What type of vulnerability is CVE-2025-64217?
CVE-2025-64217 is classified as a Cross-site Scripting (XSS) vulnerability, affecting input handling in web page generation.
Which versions of the Photography theme are affected by CVE-2025-64217?
CVE-2025-64217 affects all versions of the ThemeGoods Photography theme from n/a through 7.7.2.
Can CVE-2025-64217 be exploited remotely?
Yes, CVE-2025-64217 can be exploited remotely, allowing attackers to execute malicious scripts on the user’s browser.