CVE-2025-23714: WordPress AppReview plugin <= 0.2.9 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AppReview allows Reflected XSS. This issue affects AppReview: from n/a through 0.2.9.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in podspod AppReview appreview allows Reflected XSS.This issue affects AppReview: from n/a through <= 0.2.9.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23714?
CVE-2025-23714 is classified as a medium severity reflected Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-23714?
To fix CVE-2025-23714, update NotFound AppReview to a version higher than 0.2.9 to eliminate the vulnerability.
Which versions are affected by CVE-2025-23714?
CVE-2025-23714 affects NotFound AppReview and WordPress AppReview plugin versions up to and including 0.2.9.
What types of attacks can CVE-2025-23714 facilitate?
CVE-2025-23714 can facilitate reflected XSS attacks, allowing attackers to execute arbitrary JavaScript in users' browsers.
Is CVE-2025-23714 present in the latest version?
No, CVE-2025-23714 is not present in versions of NotFound AppReview or WordPress AppReview plugin released after 0.2.9.