First published: Tue Apr 15 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound SEO Tools allows Reflected XSS. This issue affects SEO Tools: from n/a through 4.0.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound SEO Tools | >=n/a<=4.0.7 | |
WordPress SEO Tools | <=4.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-30984 is rated as high due to its potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-30984, update NotFound SEO Tools to version 4.0.8 or later.
The potential impacts include unauthorized execution of scripts in users' browsers leading to data theft or session hijacking.
CVE-2025-30984 affects users of NotFound SEO Tools versions from n/a to 4.0.7 as well as the WordPress SEO Tools plugin up to version 4.0.7.
Yes, CVE-2025-30984 is a known vulnerability that has been publicly disclosed and has a CVE identifier.