First published: Wed Mar 26 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Driving Directions allows Reflected XSS. This issue affects Driving Directions: from n/a through 1.4.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Driving Directions | <=1.4.4 | |
WordPress Driving Directions | <=1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28903 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
To fix CVE-2025-28903, update NotFound Driving Directions or WordPress Driving Directions to version 1.4.5 or later.
The potential impacts of CVE-2025-28903 include triggering malicious scripts that can steal information from users.
CVE-2025-28903 affects NotFound Driving Directions and WordPress Driving Directions up to version 1.4.4.
Yes, user data can be at risk due to possible execution of malicious scripts through the reflected XSS vulnerability in CVE-2025-28903.