First published: Sun Feb 16 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ad Inserter Pro allows Reflected XSS. This issue affects Ad Inserter Pro: from n/a through 2.7.39.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Ad Inserter Pro | <=2.7.39 | |
NotFound Ad Inserter Pro | <=2.7.39 |
Update the WordPress Ad Inserter Pro wordpress plugin to the latest available version (at least 2.8.0).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22680 has a high severity rating due to its potential for reflected cross-site scripting (XSS).
To fix CVE-2025-22680, ensure you update NotFound Ad Inserter Pro to the latest version beyond 2.7.39.
CVE-2025-22680 is classified as a Cross-site Scripting (XSS) vulnerability that allows reflected attacks.
CVE-2025-22680 affects all versions of Ad Inserter Pro up to and including 2.7.39.
Yes, CVE-2025-22680 can lead to data compromise by allowing attackers to execute malicious scripts in the user’s browser.