RULE(RULE ID:338836)

Rule General Information
Release Date: 2025-04-29
Rule Name: WordPress Plugin Beam me up Scotty Back to Top Button Cross Site Scripting Vulnerability (CVE-2025-31864)
Severity:
CVE ID:
Rule Protection Details
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Out the Box Beam me up Scotty – Back to Top Button allows Stored XSS. This issue affects Beam me up Scotty – Back to Top Button: from n/a through 1.0.23.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://patchstack.com/database/wordpress/plugin/beam-me-up-scotty/vulnerability/wordpress-beam-me-up-scotty-back-to-top-button-plugin-1-0-23-cross-site-scripting-xss-vulnerability?_s_id=cve
Solutions
Please contact the software vendor to update the software patch.