First published: Mon Mar 03 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound IE CSS3 Support allows Reflected XSS. This issue affects IE CSS3 Support: from n/a through 2.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound IE CSS3 Support | <=2.0.1 | |
WordPress IE CSS3 Support Plugin | <=2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26589 is classified as a reflected Cross-site Scripting (XSS) vulnerability, which can potentially lead to unauthorized access and abuse of user data.
To resolve CVE-2025-26589, you should upgrade the NotFound IE CSS3 Support or WordPress IE CSS3 Support Plugin to version 2.0.2 or later.
CVE-2025-26589 affects NotFound IE CSS3 Support and WordPress IE CSS3 Support Plugin versions up to and including 2.0.1.
The vulnerability can allow attackers to inject arbitrary scripts into the web pages, potentially leading to session hijacking or data theft.
Yes, CVE-2025-26589 can be easily exploited as it involves reflected XSS, which typically does not require authenticated access.