CVE-2025-1232HIGH 8.8EPSS p75.4%
CVE-2025-1232CVE-2025-1232
Description
The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 1.78% probability of exploitation · percentile 75.4% · 2026-06-19T12:03:05Z |
| Published | 2025-03-19 |
| Last modified | 2025-05-09 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')cwe-79 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.