CVE-2025-64365: WordPress Ohio Extra plugin <= 3.6.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in colabrio Ohio Extra ohio-extra allows DOM-Based XSS.This issue affects Ohio Extra: from n/a through <= 3.6.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64365?
CVE-2025-64365 is classified as a medium severity vulnerability due to its potential for enabling Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-64365?
To fix CVE-2025-64365, update Colabrio Ohio Extra or WordPress Ohio Extra to version 3.6.1 or later.
What is the impact of CVE-2025-64365?
The impact of CVE-2025-64365 includes the risk of attackers executing malicious scripts in the context of the user's browser.
Which versions are affected by CVE-2025-64365?
CVE-2025-64365 affects all versions of Colabrio Ohio Extra and WordPress Ohio Extra from n/a up to and including 3.6.0.
Is CVE-2025-64365 present in both Colabrio and WordPress versions?
Yes, CVE-2025-64365 is present in both Colabrio Ohio Extra and WordPress Ohio Extra, specifically versions up to 3.6.0.