First published: Wed Mar 26 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NS Simple Intro Loader allows Reflected XSS. This issue affects NS Simple Intro Loader: from n/a through 2.2.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound NS Simple Intro Loader | <=2.2.3 | |
WordPress NS Simple Intro Loader | <=2.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23459 is classified as a Reflected Cross-Site Scripting (XSS) vulnerability which can have severe implications for web application security.
To fix CVE-2025-23459, upgrade the NotFound NS Simple Intro Loader to version 2.2.4 or later.
CVE-2025-23459 affects all versions of NS Simple Intro Loader from n/a through 2.2.3.
Reflected XSS, as demonstrated in CVE-2025-23459, occurs when user input is improperly handled and reflected back to the browser, allowing an attacker to execute malicious scripts.
No, CVE-2025-23459 also affects the WordPress version of NS Simple Intro Loader up to version 2.2.3.