PT-2025-44355 · WordPress · Plausible Tracking

·

CVE-2025-10927

·

Published

2025-10-29

·

Updated

2025-10-30

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal Plausible tracking versions prior to 1.0.2
Description The Plausible tracking component contains a flaw due to improper input neutralization during web page generation, leading to a Cross-Site Scripting (XSS) issue. This allows for the execution of malicious scripts within the context of a user's browser. The affected component is Plausible tracking.
Recommendations Update to version 1.0.2 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10927
DRUPAL-CONTRIB-2025-107
GHSA-PR6M-QWRR-MRW9

Affected Products

Plausible Tracking