Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.8.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-2933 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.8.0.
Fixes

Solution

Update the WordPress Verge3D wordpress plugin to the latest available version (at least 4.8.1).


Workaround

No workaround given by the vendor.

History

Tue, 21 Jan 2025 14:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.8.0.
Title WordPress Verge3D Publishing and E-Commerce Plugin <= 4.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-02-06T16:56:02.864Z

Reserved: 2025-01-07T21:03:35.333Z

Link: CVE-2025-22709

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-01-21T14:15:10.823

Modified: 2025-01-21T14:15:10.823

Link: CVE-2025-22709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses