CVE-2025-8046: Injection Guard < 1.2.8 - Reflected XSS via $_SERVER['REQUEST_URI']
Published Aug 14, 2025
·Updated
The Injection Guard WordPress plugin before 1.2.8 does not escape the $SERVER['REQUESTURI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Affected Software
2 affected components
Injection Guard WordPress plugin<1.2.8
Fahadmahmood Injection Guard Wordpress<1.2.8
Event History
Aug 14, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-8046?
CVE-2025-8046 is classified as a medium severity vulnerability due to the potential for reflected cross-site scripting.
2
How do I fix CVE-2025-8046?
To fix CVE-2025-8046, update the Injection Guard WordPress plugin to version 1.2.8 or later.
3
What exploitation risks are associated with CVE-2025-8046?
CVE-2025-8046 exposes users to reflected cross-site scripting attacks, allowing attackers to execute malicious scripts.
4
Which versions of the Injection Guard WordPress plugin are vulnerable to CVE-2025-8046?
Versions of the Injection Guard WordPress plugin prior to 1.2.8 are vulnerable to CVE-2025-8046.
5
What is the affected software for CVE-2025-8046?
CVE-2025-8046 affects the Injection Guard WordPress plugin versions before 1.2.8.