First published: Tue Feb 18 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget allows Stored XSS. This issue affects Smartarget: from n/a through 1.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Smartarget | >n/a<=1.4 | |
WordPress Smartarget.online Integration | <=1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22650 has been rated as a high severity vulnerability due to its potential for stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-22650, update the Smartarget plugin to the latest version beyond 1.4 that addresses this vulnerability.
CVE-2025-22650 can enable attackers to conduct stored XSS attacks, potentially allowing them to inject malicious scripts into web pages.
CVE-2025-22650 affects all versions of Smartarget from n/a through 1.4.
CVE-2025-22650 primarily affects the Erez Hadas-Sonnenschein Smartarget and the WordPress Smartarget.online Integration.