PT-2025-11664 · Unknown · Site Reviews

Dmitry Ignatyev

·

Published

2025-03-19

·

Updated

2025-05-09

·

CVE-2025-1232

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Site Reviews WordPress plugin versions prior to 7.2.5
Description The issue concerns the Site Reviews WordPress plugin, which does not properly sanitise and escape some of its review fields. This could allow unauthenticated users to perform Stored XSS attacks.
Recommendations For versions prior to 7.2.5, update to version 7.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the review fields until a patch is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1232

Affected Products

Site Reviews