First published: Wed Jan 22 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Jet Skinner for BuddyPress allows Reflected XSS. This issue affects Jet Skinner for BuddyPress: from n/a through 1.2.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Jet Skinner for BuddyPress | <=1.2.5 | |
NotFound Jet Skinner for BuddyPress | <=1.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23706 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
To address CVE-2025-23706, update the NotFound Jet Skinner for BuddyPress to version 1.2.6 or later.
CVE-2025-23706 affects versions up to and including 1.2.5 of NotFound Jet Skinner for BuddyPress.
CVE-2025-23706 is an improper neutralization of input during web page generation leading to reflected XSS.
Users of NotFound Jet Skinner for BuddyPress versions 1.2.5 or earlier are at risk due to CVE-2025-23706.