CVE-2025-31835
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-31835 is a Cross-Site Scripting (XSS) vulnerability affecting the WP Plugin Info Card from version n/a through 5.2.5. This issue arises due to improper neutralization of user input during the generation of web pages. An attacker can exploit this vulnerability to inject malicious scripts into a victim's browser, potentially stealing sensitive data or taking control of the user's account. The DOM-Based XSS attack can occur when a web application fails to properly encode user input, allowing attackers to inject scripts that run in the victim's browser. Users are advised to update WP Plugin Info Card to a secure version as soon as possible to mitigate the risk of this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress