First published: Mon Mar 03 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Staff Directory Plugin: Company Directory allows Stored XSS. This issue affects Staff Directory Plugin: Company Directory: from n/a through 4.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Staff Directory Plugin: Company Directory | <=4.3 | |
NotFound Staff Directory Plugin: Company Directory | <=4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-25165 is considered high due to its exploitation potential through stored cross-site scripting.
To fix CVE-2025-25165, update the NotFound Staff Directory Plugin: Company Directory to the latest version that addresses this vulnerability.
CVE-2025-25165 affects all versions of the NotFound Staff Directory Plugin: Company Directory up to and including version 4.3.
CVE-2025-25165 is classified as a Cross-Site Scripting (XSS) vulnerability, specifically a stored XSS.
Users of the NotFound Staff Directory Plugin: Company Directory, especially those using versions 4.3 or earlier, are impacted by CVE-2025-25165.