First published: Thu Apr 03 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Social Share And Social Locker allows Reflected XSS. This issue affects Social Share And Social Locker: from n/a through 1.4.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Social Share And Social Locker | <=1.4.1 | |
WordPress Social Share And Social Locker | <=1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31902 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
To fix CVE-2025-31902, update the NotFound Social Share And Social Locker plugin to a version higher than 1.4.1.
CVE-2025-31902 affects NotFound Social Share And Social Locker versions up to and including 1.4.1.
CVE-2025-31902 is an Improper Neutralization of Input During Web Page Generation vulnerability leading to reflected XSS.
Users of the NotFound Social Share And Social Locker plugin versions 1.4.1 and earlier are impacted by CVE-2025-31902.