First published: Fri Jan 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound CBX Accounting & Bookkeeping allows Reflected XSS. This issue affects CBX Accounting & Bookkeeping: from n/a through 1.3.14.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress CBX Accounting & Bookkeeping plugin | >undefined | |
WordPress CBX Accounting & Bookkeeping plugin | <=1.3.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23622 is classified as a moderate severity vulnerability due to the potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-23622, update the CBX Accounting & Bookkeeping plugin to the latest version or apply a patch if available.
CVE-2025-23622 affects CBX Accounting & Bookkeeping from its initial version up to 1.3.14.
CVE-2025-23622 is a Reflected Cross-site Scripting (XSS) vulnerability.
Yes, CVE-2025-23622 can be exploited remotely, allowing attackers to execute scripts in the user's browser.