Unrated severityNVD Advisory· Published Aug 22, 2025· Updated Jan 9, 2026
WP Talroo <= 2.4 - Reflected XSS
CVE-2025-8281
Description
The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin and unauthenticated users.
Affected products
2- WordPress/WP Talroodescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/36b9305e-e086-4edb-bff9-d181ea316389/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.