PT-2025-54294 · WordPress · Tomas Wordpress Tooltips

Zaim

·

Published

2025-12-31

·

Updated

2025-12-31

·

CVE-2025-63005

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tomas WordPress Tooltips versions through 10.7.9
Description The software contains a flaw related to improper input handling during web page generation, specifically a Stored Cross-site Scripting (XSS) issue. This allows for the injection of malicious scripts into web pages. The vulnerability affects the way user-supplied data is processed and displayed, potentially enabling an attacker to execute arbitrary code within the context of a user's browser. The affected component is susceptible to attacks where malicious code is stored on the target server and then delivered to users when they view the affected page.
Recommendations Update Tomas WordPress Tooltips to a version later than 10.7.9.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63005

Affected Products

Tomas Wordpress Tooltips