PT-2025-54294 · WordPress · Tomas Wordpress Tooltips
Zaim
·
Published
2025-12-31
·
Updated
2025-12-31
·
CVE-2025-63005
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Tomas WordPress Tooltips versions through 10.7.9
Description
The software contains a flaw related to improper input handling during web page generation, specifically a Stored Cross-site Scripting (XSS) issue. This allows for the injection of malicious scripts into web pages. The vulnerability affects the way user-supplied data is processed and displayed, potentially enabling an attacker to execute arbitrary code within the context of a user's browser. The affected component is susceptible to attacks where malicious code is stored on the target server and then delivered to users when they view the affected page.
Recommendations
Update Tomas WordPress Tooltips to a version later than 10.7.9.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tomas Wordpress Tooltips