CVE-2026-25341: WordPress RSFirewall! plugin <= 1.1.45 - Cross Site Scripting (XSS) vulnerability
Published Mar 25, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSJoomla! RSFirewall! rsfirewall allows Stored XSS.This issue affects RSFirewall!: from n/a through <= 1.1.45.
Affected Software
1 affected component
rsjoomla RSFirewall!<=1.1.45
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25341?
The severity of CVE-2026-25341 is classified as high with a CVSS score of 7.1.
2
What type of vulnerability is identified by CVE-2026-25341?
CVE-2026-25341 identifies a Cross Site Scripting (XSS) vulnerability in the RSFirewall! plugin.
3
How do I fix CVE-2026-25341?
To fix CVE-2026-25341, update the RSFirewall! plugin to version 1.1.46 or later.
4
Which versions of the RSFirewall! plugin are affected by CVE-2026-25341?
RSFirewall! plugin versions from n/a to 1.1.45 are affected by CVE-2026-25341.
5
What impact does CVE-2026-25341 have on websites?
CVE-2026-25341 allows for stored Cross Site Scripting attacks, which can lead to unauthorized access or data theft.