6.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Description
The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individual_user' parameter in all versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Basic Information
ID
CVE-2025-11922
Source
Wordfence
Published
Nov 1, 2025 at 01:47
Affected Product
Vendor
j_3rk
Product
Inactive Logout
Version
*
Affected Versions
j_3rk Inactive Logout *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/fde110ae-c559-4d45-91c0-a3dd5ff05c4d
- plugins.trac.wordpress.org /browser/inactive-logout/trunk/core/Controllers/AdminController.php
- plugins.trac.wordpress.org /browser/inactive-logout/trunk/core/Controllers/Admin/StoreController.php
- plugins.trac.wordpress.org /browser/inactive-logout/trunk/views/tabs/tpl-inactive-logout-advanced.php
- plugins.trac.wordpress.org /changeset