Reflected Cross-site Scripting Vulnerability in NotFound WP Social Links
CVE-2025-23570
7.1HIGH
Summary
The NotFound WP Social Links plugin is vulnerable to reflected Cross-site Scripting (XSS) attacks due to improper input sanitization during web page generation. This vulnerability allows an attacker to inject malicious scripts via crafted URLs, impacting users visiting the affected site. Successful exploitation facilitates session hijacking and other malicious actions that compromise user data and site integrity.
Affected Version(s)
WP Social Links <= 0.3.1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)