CVE-2025-31595
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-31595 is a Cross-site Scripting (XSS) vulnerability affecting the Timeline Event History plugin for WordPress. The issue, which allows Stored XSS attacks, lies in the plugin's improper handling of user inputs during web page generation. Attackers can exploit this vulnerability to inject malicious scripts into a victim's web browser, potentially leading to data theft or unauthorized actions. The affected versions of the plugin range from not available to 3.2. Users are strongly advised to update to a patched version or disable the plugin as a temporary measure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.