First published: Wed Jan 22 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Content Planner allows Reflected XSS. This issue affects Content Planner: from n/a through 1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Content Planner | <=1.0 | |
WordPress Content Planner | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23631 is classified as a reflected cross-site scripting (XSS) vulnerability, which can lead to unauthorized actions on behalf of a user.
To fix CVE-2025-23631, ensure you update the NotFound Content Planner to a version that addresses this vulnerability.
CVE-2025-23631 affects users of NotFound Content Planner and WordPress Content Planner versions up to 1.0.
Cross-site scripting in CVE-2025-23631 refers to the vulnerability that allows attackers to inject malicious scripts into web pages viewed by users.
The potential impacts of CVE-2025-23631 include data theft, session hijacking, and the implementation of unauthorized actions through user accounts.