CVE-2025-0688

The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mynamedia:spiritual_gifts_survey_\(and_optional_s.h.a.p.e_survey\):*:*:*:*:*:wordpress:*:*

History

28 May 2025, 15:32

Type Values Removed Values Added
CWE CWE-79
CPE cpe:2.3:a:mynamedia:spiritual_gifts_survey_\(and_optional_s.h.a.p.e_survey\):*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/1e2b77c3-ad45-4734-998a-c1722ebd1f4f/ - () https://wpscan.com/vulnerability/1e2b77c3-ad45-4734-998a-c1722ebd1f4f/ - Exploit, Third Party Advisory
First Time Mynamedia
Mynamedia spiritual Gifts Survey \(and Optional S.h.a.p.e Survey\)

20 May 2025, 20:15

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/1e2b77c3-ad45-4734-998a-c1722ebd1f4f/ - () https://wpscan.com/vulnerability/1e2b77c3-ad45-4734-998a-c1722ebd1f4f/ -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

16 May 2025, 14:42

Type Values Removed Values Added
Summary
  • (es) El complemento Spiritual Gifts Survey (and optional S.H.A.P.E survey) de WordPress hasta la versión 0.9.10 no depura ni escapa un parámetro antes de mostrarlo nuevamente en la página, lo que genera un Cross-Site Scripting reflejado que solo se puede usar contra usuarios no autenticados.

15 May 2025, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:16

Updated : 2025-05-28 15:32


NVD link : CVE-2025-0688

Mitre link : CVE-2025-0688

CVE.ORG link : CVE-2025-0688


JSON object : View

Products Affected

mynamedia

  • spiritual_gifts_survey_\(and_optional_s.h.a.p.e_survey\)
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')