CVE-2025-69302: WordPress DesignThemes Core Features plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Core Features designthemes-core-features allows Reflected XSS.This issue affects DesignThemes Core Features: from n/a through <= 2.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69302?
CVE-2025-69302 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
What type of vulnerability is CVE-2025-69302?
CVE-2025-69302 is a reflected cross-site scripting (XSS) vulnerability affecting the DesignThemes Core Features plugin.
Who is affected by CVE-2025-69302?
CVE-2025-69302 affects users of the WordPress DesignThemes Core Features plugin version 2.3 and earlier.
How do I fix CVE-2025-69302?
To fix CVE-2025-69302, update the DesignThemes Core Features plugin to the latest version that addresses this vulnerability.
What is the impact of exploitation of CVE-2025-69302?
Exploitation of CVE-2025-69302 can allow attackers to execute arbitrary JavaScript code on behalf of the user, potentially compromising sensitive information.