First published: Mon Mar 03 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Easy Post Mailer allows Reflected XSS. This issue affects WP Easy Post Mailer: from n/a through 0.64.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound WP Easy Post Mailer | <=0.64 | |
NotFound WP Easy Post Mailer | <=0.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23956 has a medium severity rating due to its potential to allow reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-23956, upgrade your NotFound WP Easy Post Mailer plugin to version 0.65 or later.
CVE-2025-23956 affects all versions of NotFound WP Easy Post Mailer up to and including 0.64.
CVE-2025-23956 is classified as a reflected cross-site scripting (XSS) vulnerability.
Attackers can exploit CVE-2025-23956 to execute malicious scripts in the context of users visiting compromised web pages.