First published: Wed Mar 26 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Custom Smilies allows Stored XSS. This issue affects Custom Smilies: from n/a through 2.9.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Custom Smilies | <2.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28917 has been classified as a critical severity vulnerability due to its potential for stored Cross-site Scripting (XSS) attacks.
To remediate CVE-2025-28917, update the NotFound Custom Smilies plugin to version 2.9.3 or later.
CVE-2025-28917 can allow attackers to execute arbitrary JavaScript code in the context of the affected site, potentially leading to data theft or session hijacking.
All versions of NotFound Custom Smilies up to and including 2.9.2 are vulnerable to CVE-2025-28917.
Yes, CVE-2025-28917 is considered an easy target due to its nature as a stored XSS vulnerability, allowing attackers to exploit it remotely.