First published: Mon Mar 03 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in NotFound Curated Search allows Stored XSS. This issue affects Curated Search: from n/a through 1.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Curated Search | >=n/a<=1.2 | |
WordPress Curated Search | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23502 is considered a critical vulnerability due to its potential for Cross-Site Request Forgery leading to Stored XSS.
To fix CVE-2025-23502, update NotFound Curated Search to version 1.3 or later and ensure proper CSRF protections are implemented.
The potential impacts of CVE-2025-23502 include unauthorized actions being performed on behalf of users and execution of arbitrary scripts in their sessions.
CVE-2025-23502 affects all versions of NotFound Curated Search from n/a through 1.2.
Users and administrators of NotFound Curated Search and WordPress Curated Search up to version 1.2 are affected by CVE-2025-23502.