CVE-2025-31595

CVSS 3.1 Score 6.5 of 10 (medium)

Attack Complexity low
Scope changed
Confidentiality low
Integrity low
Availability low
Privileges Required low

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 79

Summary

CVE-2025-31595 is a Cross-site Scripting (XSS) vulnerability affecting the Timeline Event History plugin for WordPress. The issue, which allows Stored XSS attacks, lies in the plugin's improper handling of user inputs during web page generation. Attackers can exploit this vulnerability to inject malicious scripts into a victim's web browser, potentially leading to data theft or unauthorized actions. The affected versions of the plugin range from not available to 3.2. Users are strongly advised to update to a patched version or disable the plugin as a temporary measure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share