First published: Fri Feb 14 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wjharil AdsMiddle allows Reflected XSS. This issue affects AdsMiddle: from n/a through 1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
wjharil AdsMiddle | <=1.0 | |
WordPress | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23648 is classified as a moderate severity reflected Cross-site Scripting (XSS) vulnerability.
CVE-2025-23648 affects wjharil AdsMiddle up to and including version 1.0.
To fix CVE-2025-23648, update to the latest version of wjharil AdsMiddle that addresses this XSS vulnerability.
Yes, successful exploitation of CVE-2025-23648 could allow attackers to execute arbitrary scripts in the context of the victim's browser.
Cross-site Scripting (XSS) is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.