Reflected Cross-site Scripting Vulnerability in NotFound WP Social Links
CVE-2025-23570

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
3 March 2025

Summary

The NotFound WP Social Links plugin is vulnerable to reflected Cross-site Scripting (XSS) attacks due to improper input sanitization during web page generation. This vulnerability allows an attacker to inject malicious scripts via crafted URLs, impacting users visiting the affected site. Successful exploitation facilitates session hijacking and other malicious actions that compromise user data and site integrity.

Affected Version(s)

WP Social Links <= 0.3.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.