PT-2025-38823 · WordPress · Chad Butler Wp-Members

Theviper17

·

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-57973

CVSS v3.1

5.5

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Chad Butler WP-Members versions through 3.5.4.2
Description The software contains a flaw related to improper input handling during web page generation, specifically a Cross-site Scripting issue. This allows for Stored XSS attacks. The issue involves the injection of malicious scripts into web pages, potentially compromising user data and system security.
Recommendations Update Chad Butler WP-Members to a version later than 3.5.4.2.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-57973

Affected Products

Chad Butler Wp-Members