First published: Wed Mar 26 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Google Plus allows Reflected XSS. This issue affects Google Plus: from n/a through 1.0.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Plus | <=1.0.2 | |
WordPress Google Plus Plugin | <=1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23964 is classified as a reflected cross-site scripting (XSS) vulnerability.
To mitigate CVE-2025-23964, update the Google Plus Plugin to the latest version beyond 1.0.2.
CVE-2025-23964 affects Google Plus up to version 1.0.2 and the WordPress Google Plus Plugin up to version 1.0.2.
CVE-2025-23964 allows attackers to execute reflected XSS attacks, potentially compromising user data.
No, CVE-2025-23964 indicates that user input is improperly sanitized, making it vulnerable to XSS attacks.