Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12299 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer List Last Changes allows Stored XSS. This issue affects List Last Changes: from n/a through 1.2.1. |
Solution
Update the WordPress List Last Changes plugin to the latest available version (at least 1.2.2).
Workaround
No workaround given by the vendor.
Wed, 30 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rolandbaer
Rolandbaer list Last Changes |
|
| CPEs | cpe:2.3:a:rolandbaer:list_last_changes:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Rolandbaer
Rolandbaer list Last Changes |
Tue, 22 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Apr 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer List Last Changes allows Stored XSS. This issue affects List Last Changes: from n/a through 1.2.1. | |
| Title | WordPress List Last Changes <= 1.2.1 - Cross Site Scripting (XSS) Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-04-22T13:59:09.727Z
Reserved: 2025-04-22T09:21:32.319Z
Link: CVE-2025-46238
Updated: 2025-04-22T13:59:02.425Z
Status : Analyzed
Published: 2025-04-22T10:15:17.317
Modified: 2025-04-30T15:27:17.047
Link: CVE-2025-46238
No data.
OpenCVE Enrichment
No data.
EUVD