First published: Wed Jan 22 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP IMAP Auth allows Reflected XSS. This issue affects WP IMAP Auth: from n/a through 4.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WP IMAP Auth | <=4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23506 is classified as a reflected cross-site scripting (XSS) vulnerability.
To fix CVE-2025-23506, update WP IMAP Auth to a version later than 4.0.1.
CVE-2025-23506 affects WP IMAP Auth versions up to and including 4.0.1.
CVE-2025-23506 can allow attackers to execute reflected cross-site scripting (XSS) attacks.
Yes, exploiting CVE-2025-23506 typically requires user interaction to trigger the XSS vulnerability.