First published: Mon Mar 03 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Uncomplicated SEO allows Reflected XSS. This issue affects Uncomplicated SEO: from n/a through 1.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Uncomplicated SEO | <=1.2 | |
WordPress Uncomplicated SEO plugin | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25158 is classified as a high-severity vulnerability due to its ability to allow reflected cross-site scripting (XSS).
To fix CVE-2025-25158, update NotFound Uncomplicated SEO to the latest version beyond 1.2 or apply a security patch if available.
CVE-2025-25158 affects NotFound Uncomplicated SEO versions from n/a through 1.2 inclusive.
Yes, CVE-2025-25158 can be exploited remotely through crafted requests that lead to cross-site scripting attacks.
Mitigations for CVE-2025-25158 include implementing input validation and user input sanitization to prevent XSS.