WordPress · Plausible Tracking · CVE-2025-10927
**Name of the Vulnerable Software and Affected Versions**
Drupal Plausible tracking versions prior to 1.0.2
**Description**
The Plausible tracking component contains a flaw due to improper input neutralization during web page generation, leading to a Cross-Site Scripting (XSS) issue. This allows for the execution of malicious scripts within the context of a user's browser. The affected component is Plausible tracking.
**Recommendations**
Update to version 1.0.2 or later.