CVE-2025-23633: WordPress WP Database Audit plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in khanhtruong WP Database Audit database-audit allows Reflected XSS.This issue affects WP Database Audit: from n/a through <= 1.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Database Audit allows Reflected XSS. This issue affects WP Database Audit: from n/a through 1.0.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23633?
CVE-2025-23633 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-23633?
To mitigate CVE-2025-23633, update the WP Database Audit plugin to a version beyond 1.0.
What versions are affected by CVE-2025-23633?
CVE-2025-23633 affects WP Database Audit versions up to and including 1.0.
What type of attack does CVE-2025-23633 allow?
CVE-2025-23633 allows for reflected cross-site scripting (XSS) attacks.
Can CVE-2025-23633 compromise user data?
Yes, CVE-2025-23633 can potentially expose user data by executing malicious scripts in the user's browser.