First published: Mon Mar 03 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ni WooCommerce Sales Report Email allows Reflected XSS. This issue affects Ni WooCommerce Sales Report Email: from n/a through 3.1.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ni WooCommerce Sales Report Email | <=3.1.4 | |
WordPress WooCommerce Sales Report Email | <=3.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23481 has a high severity due to its potential for Reflected Cross-Site Scripting (XSS) attacks.
To fix CVE-2025-23481, update the Ni WooCommerce Sales Report Email plugin to the latest version beyond 3.1.4.
CVE-2025-23481 affects Ni WooCommerce Sales Report Email versions up to 3.1.4.
CVE-2025-23481 is classified as a Reflected Cross-Site Scripting (XSS) vulnerability.
The potential impact of CVE-2025-23481 includes unauthorized access and malicious actions executed on the user's browser.