CVE-2025-64224: WordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Reflected XSS.This issue affects Grand Conference Theme Custom Post Type: from n/a through < 2.6.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64224?
CVE-2025-64224 has a medium severity rating due to its potential to allow reflected cross-site scripting attacks.
How do I fix CVE-2025-64224?
To fix CVE-2025-64224, upgrade the Grand Conference Theme Custom Post Type to version 2.6.4 or later.
What does CVE-2025-64224 affect?
CVE-2025-64224 specifically affects versions of the Grand Conference Theme Custom Post Type prior to 2.6.4.
What is the nature of the issue in CVE-2025-64224?
CVE-2025-64224 involves improper neutralization of user input, leading to reflected cross-site scripting (XSS) vulnerabilities.
Can CVE-2025-64224 be exploited by attackers?
Yes, CVE-2025-64224 can be exploited by attackers to execute arbitrary JavaScript in the context of affected users' browsers.