First published: Thu Jan 16 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Mozilla Web Push allows Stored XSS.This issue affects Web Push: from n/a through 1.4.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Web Push | <=1.4.0 | |
WordPress Web Push plugin | <=1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23720 has a medium severity due to its potential to allow Stored XSS via CSRF in affected versions.
To fix CVE-2025-23720, update Mozilla Web Push or WordPress Web Push plugin to a version higher than 1.4.0.
CVE-2025-23720 affects Mozilla Web Push and WordPress Web Push plugin versions up to and including 1.4.0.
CVE-2025-23720 is caused by a Cross-Site Request Forgery (CSRF) issue that can lead to Stored XSS.
Yes, if you are using the affected versions of Mozilla Web Push or the WordPress Web Push plugin, your website could be vulnerable to CVE-2025-23720.