Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25526 | The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin and unauthenticated users. |
Fri, 16 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Boybawang
Boybawang wp Talroo |
|
| CPEs | cpe:2.3:a:boybawang:wp_talroo:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Boybawang
Boybawang wp Talroo |
Fri, 09 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Sat, 23 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Fri, 22 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 22 Aug 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin and unauthenticated users. | |
| Title | WP Talroo <= 2.4 - Reflected XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-01-09T20:20:08.756Z
Reserved: 2025-07-28T13:48:59.108Z
Link: CVE-2025-8281
Updated: 2025-08-22T14:40:36.736Z
Status : Analyzed
Published: 2025-08-22T06:15:33.563
Modified: 2026-01-16T21:05:35.663
Link: CVE-2025-8281
No data.
OpenCVE Enrichment
Updated: 2025-08-23T10:55:34Z
EUVD