First published: Thu Jan 16 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in closed SOCIAL.NINJA allows Stored XSS. This issue affects SOCIAL.NINJA: from n/a through 0.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress SOCIAL.NINJA | <=0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23907 is classified as a critical vulnerability due to its potential for Stored Cross-site Scripting (XSS).
To fix CVE-2025-23907, update the SOCIAL.NINJA plugin to a version above 0.2 or implement input sanitization measures.
CVE-2025-23907 affects all versions of SOCIAL.NINJA from n/a through 0.2 used in WordPress.
CVE-2025-23907 is a Cross-site Scripting (XSS) vulnerability related to improper input neutralization during web page generation.
Yes, CVE-2025-23907 can lead to data breaches by allowing attackers to execute malicious scripts in users' browsers.