Reflected XSS Vulnerability in My Favorite Car Plugin by Dimitar Atanasov
CVE-2025-23636
What is CVE-2025-23636?
A reflected Cross-Site Scripting (XSS) vulnerability exists in the My Favorite Car plugin developed by Dimitar Atanasov. This security flaw allows attackers to inject malicious scripts into web pages that are then reflected back to users. The vulnerability is particularly concerning as it operates on various versions of the plugin, including versions from n/a through 1.0. Exploiting this vulnerability can result in unauthorized access to user data or compromised user sessions, highlighting the importance of prompt updates and security practices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
My Favorite Car <= 1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved