PT-2025-54329 · Viitorcloud Technologies Pvt · Add Featured Image Custom Link
Nabil Irawan
·
Published
2025-12-31
·
Updated
2026-01-01
·
CVE-2025-62119
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ViitorCloud Technologies Pvt Ltd Add Featured Image Custom Link versions through 2.0.0
Description
The software contains a flaw related to improper input handling during web page generation, leading to a Cross-site Scripting (XSS) condition. This specific instance is a DOM-Based XSS, potentially allowing attackers to inject malicious scripts into web pages viewed by other users.
Recommendations
Versions prior to 2.0.0 should be updated.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Add Featured Image Custom Link