CVE-2025-1232
Site Reviews < 7.2.5 - Unauthenticated Stored XSS
Record summary
CVE-2025-1232 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 19, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Site ReviewsDefault status: unaffected | CVE List | Before 7.2.5 | affected |
Nuclei templates
1ProjectDiscoveryHIGHSite Reviews < 7.2.5 - Unauthenticated Stored XSSCVSS 8.8
Site Reviews WordPress plugin before 7.2.5 contains a stored cross-site scripting caused by improper sanitization and escaping of review fields, letting unauthenticated users execute malicious scripts, exploit requires no authentication.
Impact
Unauthenticated users can execute malicious scripts in the context of site visitors, potentially leading to session hijacking or defacement.
Remediation
Update to version 7.2.5 or later.
Source: ProjectDiscovery