First published: Tue Jan 21 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Private Messages for UserPro allows Reflected XSS. This issue affects Private Messages for UserPro: from n/a through 4.10.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Private Messages for UserPro | <=4.10.0 | |
UserPro Private Messages | <=4.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22322 is classified as a high severity vulnerability due to its ability to facilitate reflected cross-site scripting attacks.
To fix CVE-2025-22322, update the Private Messages for UserPro plugin to version 4.10.1 or later.
CVE-2025-22322 allows attackers to execute arbitrary JavaScript in users' browsers via reflected cross-site scripting.
CVE-2025-22322 affects all versions of Private Messages for UserPro up to and including 4.10.0.
Any user or website utilizing the vulnerable versions of Private Messages for UserPro is at risk of exploitation through this vulnerability.