Skip to content

Known CVE

Site Reviews < 7.2.5 - Unauthenticated Stored XSS

Site Reviews WordPress plugin before 7.2.5 contains a stored cross-site scripting caused by improper sanitization and escaping of review fields, letting unauthenticated users execute malicious scripts, exploit requires no authentication.

CVE-2025-1232

High2025CVSS 8.8CWE-79

cve2025 · wordpress · wp · wp-plugin · site-reviews · xss · stored

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website