Reflected XSS Vulnerability in Mancx AskMe Widget by NotFound
CVE-2025-23718

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
3 March 2025

Summary

The Mancx AskMe Widget by NotFound is susceptible to a reflected XSS vulnerability due to improper input handling during web page generation. This vulnerability allows attackers to execute arbitrary JavaScript code in the context of a user's browser session, potentially leading to data theft, session hijacking, or other malicious actions. The issue affects versions of the Mancx AskMe Widget up to 0.3, making it crucial for users to apply necessary updates or mitigations to enhance their website's security.

Affected Version(s)

Mancx AskMe Widget <= 0.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.