First published: Thu Jan 16 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ivo Brett – ApplyMetrics Apply with LinkedIn buttons allows DOM-Based XSS.This issue affects Apply with LinkedIn buttons: from n/a through 2.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivo Brett ApplyMetrics Apply with LinkedIn buttons | <=2.3 | |
WordPress Apply with LinkedIn buttons | <=2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23897 has been classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting (XSS).
To fix CVE-2025-23897, update the Apply with LinkedIn buttons plugin to the latest version available after 2.3.
CVE-2025-23897 affects versions of the Apply with LinkedIn buttons plugin from n/a up to and including 2.3.
Cross-site Scripting (XSS) in CVE-2025-23897 allows attackers to execute scripts in the browser of a user visiting the compromised site.
CVE-2025-23897 impacts the Ivo Brett ApplyMetrics Apply with LinkedIn buttons and WordPress Apply with LinkedIn buttons plugins.