First published: Mon Feb 03 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AIO Shortcodes allows Stored XSS. This issue affects AIO Shortcodes: from n/a through 1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound AIO Shortcodes | >n/a<=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24620 is classified as a high-severity vulnerability due to its potential for allowing stored XSS attacks.
To mitigate CVE-2025-24620, update NotFound AIO Shortcodes to version 1.3 or later.
CVE-2025-24620 is a Stored Cross-site Scripting (XSS) vulnerability that arises from improper input neutralization.
CVE-2025-24620 affects users of NotFound AIO Shortcodes versions from n/a to 1.3.
The impacts of CVE-2025-24620 include exposure to malicious scripts that could lead to data theft and site compromise.