CVE-2025-22360
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-22360 is a Cross-site Scripting (XSS) vulnerability affecting NotFound WP Azure offload. The flaw, which involves improper neutralization of user input during web page generation, allows attackers to inject malicious scripts into web pages viewed by other users. This issue potentially impacts versions of NotFound WP Azure offload ranging from n/a to 2.0. Successful exploitation could lead to unintended execution of malicious code in a user's web browser, exposing sensitive information or taking control of the user's account. Users are advised to apply the necessary patches or upgrades as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.