/Vulnerability Library

Site Reviews < 7.2.5 - Unauthenticated Stored XSS

CVE-2025-1232
Verified

Description

Site Reviews WordPress plugin before 7.2.5 contains a stored cross-site scripting caused by improper sanitization and escaping of review fields, letting unauthenticated users execute malicious scripts, exploit requires no authentication.

Severity

High

CVSS Score

8.8

Exploit Probability

2%

Affected Product

site-reviews

Published Date

February 9, 2026

Template Author

0x_akoko

CVE-2025-1232.yaml
8.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-1232
CWE ID:
cwe-79

References

https://wpscan.com/vulnerability/c4ea8357-ddd7-48ac-80c9-15b924715b14/https://nvd.nist.gov/vuln/detail/CVE-2025-1232https://research.cleantalk.org/cve-2025-1232/

Remediation Steps

Update to version 7.2.5 or later.