First published: Fri Jan 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dovy Paukstys Redux Converter allows Reflected XSS. This issue affects Redux Converter: from n/a through 1.1.3.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Redux Converter | >=n/a<1.1.3.1 | |
WordPress Redux Converter | <=1.1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23427 is classified as a reflected cross-site scripting (XSS) vulnerability.
To fix CVE-2025-23427, you should update the Redux Converter plugin to the latest version beyond 1.1.3.1.
CVE-2025-23427 affects the Redux Converter versions from n/a through 1.1.3.1.
CVE-2025-23427 can allow attackers to execute arbitrary JavaScript code in the context of the user's browser.
The vendor responsible for CVE-2025-23427 is Dovy Paukstys.