Reflected Cross-site Scripting Vulnerability in NotFound 4 Author Cheer Up Donate Plugin
CVE-2025-23670
7.1HIGH
What is CVE-2025-23670?
The NotFound 4 Author Cheer Up Donate plugin for WordPress is affected by a Reflected Cross-site Scripting vulnerability. This flaw arises from the improper neutralization of input during web page generation, allowing attackers to inject malicious scripts into the affected website. When exploited, this can potentially lead to unauthorized actions and compromise user security. Affected versions range from the initial release up to 1.3, emphasizing the need for users and site administrators to implement the latest security updates and best practices.
Affected Version(s)
4 author cheer up donate <= 1.3