PT-2026-1790 · WordPress · Loopus Wp Virtual Assistant

Published

2026-01-08

·

Updated

2026-01-08

·

CVE-2025-22725

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions loopus WP Virtual Assistant versions through 3.0
Description The software contains a flaw related to improper handling of user-supplied data when creating web pages, leading to a potential Cross-site Scripting (XSS) issue. This specific instance allows for Stored XSS, meaning malicious scripts can be stored on the target server and executed by other users.
Recommendations Update loopus WP Virtual Assistant to a version newer than 3.0.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-22725

Affected Products

Loopus Wp Virtual Assistant