CVE-2025-1232

HIGH NUCLEI

Site Reviews WP <7.2.5 - XSS

Title source: llm

Description

The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks

Nuclei Templates (1)

Site Reviews < 7.2.5 - Unauthenticated Stored XSS
HIGHVERIFIEDby 0x_Akoko
Shodan: http.component:"WordPress"
FOFA: body="site-reviews" || body="glsr-form"

Scores

CVSS v3 8.8
EPSS 0.5313
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (1)
geminilabs/site_reviews < 7.2.5
Published Mar 19, 2025
Tracked Since Feb 18, 2026