CVE-2025-66081: WordPress Head Meta Data plugin <= 20250327 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Head Meta Data head-meta-data allows Stored XSS.This issue affects Head Meta Data: from n/a through <= 20250327.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66081?
CVE-2025-66081 is a high-severity vulnerability due to its potential to allow stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-66081?
To fix CVE-2025-66081, update the Head Meta Data plugin to a version newer than 20250327.
What types of systems are affected by CVE-2025-66081?
CVE-2025-66081 affects the Head Meta Data plugin for WordPress versions up to and including 20250327.
Can CVE-2025-66081 lead to data compromise?
Yes, CVE-2025-66081 can lead to data compromise by allowing attackers to execute malicious scripts in the context of a user's browser.
How can I detect CVE-2025-66081 in my environment?
You can detect CVE-2025-66081 by scanning your WordPress installation for the Head Meta Data plugin version 20250327 or earlier.