Cross-site Scripting Vulnerability in Notely by Michael Ott
CVE-2025-60149
5.9MEDIUM
What is CVE-2025-60149?
The Notely plugin developed by Michael Ott is susceptible to a Stored Cross-site Scripting (XSS) vulnerability, allowing malicious users to inject scripts that can be executed in the browser of an unsuspecting user. This can lead to data theft or unauthorized actions on behalf of users. The vulnerability affects versions from n/a to 1.8.0, emphasizing the need for website owners to ensure their installations are updated and secured against potential exploits.
Affected Version(s)
Notely <= 1.8.0