First published: Wed Mar 26 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AuMenu allows Reflected XSS. This issue affects AuMenu: from n/a through 1.1.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound AuMenu | <=1.1.5 | |
WordPress AuMenu | <=1.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-23728 is considered medium due to its potential for reflected cross-site scripting attacks.
To fix CVE-2025-23728, update NotFound AuMenu to the latest version beyond 1.1.5 where the vulnerability is patched.
CVE-2025-23728 affects NotFound AuMenu and WordPress AuMenu versions up to 1.1.5.
Exploiting CVE-2025-23728 can lead to unauthorized script execution in the context of a user's browser.
Reflected cross-site scripting vulnerabilities like CVE-2025-23728 are relatively common in web applications.