CVE-2025-23536: WordPress Track Page Scroll plugin <= 1.0.2 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mndpsingh287 Track Page Scroll track-page-scroll allows Reflected XSS.This issue affects Track Page Scroll: from n/a through <= 1.0.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23536?
CVE-2025-23536 has a high severity level due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-23536?
To fix CVE-2025-23536, update the Track Page Scroll plugin to version 1.0.3 or later.
What are the potential impacts of CVE-2025-23536?
The impacts of CVE-2025-23536 include unauthorized data access and potential exploitation of user sessions through XSS.
Who is affected by CVE-2025-23536?
Anyone using the Mndpsingh287 Track Page Scroll plugin version 1.0.2 or earlier is affected by CVE-2025-23536.
Is there a public exploit for CVE-2025-23536?
Yes, public exploits for CVE-2025-23536 are likely in circulation, highlighting the urgency for patching.