PT-2026-1790 · WordPress · Loopus Wp Virtual Assistant

CVE-2025-22725

·

Published

2026-01-08

·

Updated

2026-01-08

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions loopus WP Virtual Assistant versions through 3.0
Description The software contains a flaw related to improper handling of user-supplied data when creating web pages, leading to a potential Cross-site Scripting (XSS) issue. This specific instance allows for Stored XSS, meaning malicious scripts can be stored on the target server and executed by other users.
Recommendations Update loopus WP Virtual Assistant to a version newer than 3.0.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-22725

Affected Products

Loopus Wp Virtual Assistant