WordPress Authentication and xmlrpc log writer Plugin <= 1.2.2 is vulnerable to Cross Site Scripting (XSS)
Discription

image
Software Authentication and xmlrpc log writer Type Plugin Vulnerable versions &lt;= 1.2.2 Fixed in N/A OWASP Top 10 A3: Injection Classification Cross Site Scripting (XSS) CVE CVE-2025-49037 Patch priority Medium CVSS severity Medium (7.1) Developer Claim ownership PSID 8ce91b6d0014 Credits Nguyen Xuan Chien Required privilege Unauthenticated Published 13 August, 2025 Expand full details Have additional information or questions about this entry? Let us know. Solution We advise to mitigate or resolve the vulnerability…Read More

Back to Main

Subscribe for the latest news: