CVE-2025-30984: WordPress SEO Tools plugin <= 4.0.7 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dzynit SEO Tools seo-automatic-seo-tools allows Reflected XSS.This issue affects SEO Tools: from n/a through <= 4.0.7.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound SEO Tools allows Reflected XSS. This issue affects SEO Tools: from n/a through 4.0.7.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30984?
The severity of CVE-2025-30984 is rated as high due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-30984?
To fix CVE-2025-30984, update NotFound SEO Tools to version 4.0.8 or later.
What are the potential impacts of CVE-2025-30984?
The potential impacts include unauthorized execution of scripts in users' browsers leading to data theft or session hijacking.
Who is affected by CVE-2025-30984?
CVE-2025-30984 affects users of NotFound SEO Tools versions from n/a to 4.0.7 as well as the WordPress SEO Tools plugin up to version 4.0.7.
Is CVE-2025-30984 a known vulnerability?
Yes, CVE-2025-30984 is a known vulnerability that has been publicly disclosed and has a CVE identifier.