CVE-2025-22680: WordPress Ad Inserter Pro plugin <= 2.7.39 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ad Inserter Pro ad-inserter-pro allows Reflected XSS.This issue affects Ad Inserter Pro: from n/a through <= 2.7.39.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ad Inserter Pro allows Reflected XSS. This issue affects Ad Inserter Pro: from n/a through 2.7.39.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22680?
CVE-2025-22680 has a high severity rating due to its potential for reflected cross-site scripting (XSS).
How do I fix CVE-2025-22680?
To fix CVE-2025-22680, ensure you update NotFound Ad Inserter Pro to the latest version beyond 2.7.39.
What type of vulnerability is CVE-2025-22680?
CVE-2025-22680 is classified as a Cross-site Scripting (XSS) vulnerability that allows reflected attacks.
What versions of Ad Inserter Pro are affected by CVE-2025-22680?
CVE-2025-22680 affects all versions of Ad Inserter Pro up to and including 2.7.39.
Can CVE-2025-22680 lead to data compromise?
Yes, CVE-2025-22680 can lead to data compromise by allowing attackers to execute malicious scripts in the user’s browser.