CVE-2025-22623: Ad Inserter - Reflected cross-site scripting (XSS)
Ad Inserter - Ad Manager and AdSense Ads 2.8.0 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/includes/dst/dst.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22623?
CVE-2025-22623 has been classified as a medium severity vulnerability due to its potential impact on web application security.
How do I fix CVE-2025-22623?
To fix CVE-2025-22623, ensure that the Ad Inserter - Ad Manager and AdSense Ads plugin is updated to the latest version that addresses this vulnerability.
What kind of vulnerability is CVE-2025-22623?
CVE-2025-22623 is a type of data validation issue where untrusted data is processed without proper validation, leading to potential security risks.
Which version of Ad Inserter is affected by CVE-2025-22623?
CVE-2025-22623 affects version 2.8.0 of the Ad Inserter - Ad Manager and AdSense Ads plugin.
What are the consequences of CVE-2025-22623?
Consequences of CVE-2025-22623 may include unauthorized data manipulation, cross-site scripting, or injection attacks if not remediated.