First published: Thu Apr 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Mok GNA Search Shortcode allows Stored XSS. This issue affects GNA Search Shortcode: from n/a through 0.9.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress GNA Search Shortcode | <=0.9.5 | |
Chris Mok GNA Search Shortcode | <=0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46540 is categorized as a high-severity vulnerability due to its potential for Stored XSS attacks.
CVE-2025-46540 allows attackers to inject malicious scripts into web pages, which can compromise user data and session integrity.
To remediate CVE-2025-46540, update the GNA Search Shortcode plugin to the latest version that addresses this vulnerability.
CVE-2025-46540 affects versions of GNA Search Shortcode from n/a to 0.9.5.
If your website is running GNA Search Shortcode version 0.9.5 or earlier, it is vulnerable to CVE-2025-46540.