Site Reviews < 7.2.5 - Unauthenticated Stored XSS
CVE-2025-1232
Verified
Description
Site Reviews WordPress plugin before 7.2.5 contains a stored cross-site scripting caused by improper sanitization and escaping of review fields, letting unauthenticated users execute malicious scripts, exploit requires no authentication.
Severity
High
CVSS Score
8.8
Exploit Probability
2%
Affected Product
site-reviews
Published Date
February 9, 2026
Template Author
0x_akoko
CVE-2025-1232.yaml
8.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-1232
CWE ID:
cwe-79
Remediation Steps
Update to version 7.2.5 or later.