CVE-2025-22683
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 3, 2025
CWE ID 79
Summary
CVE-2022-22683 is a Cross-site Scripting (XSS) vulnerability affecting WPDeveloper NotificationX. The flaw, which permits Stored XSS attacks, exists due to improper neutralization of user inputs during web page generation. This issue impacts NotificationX versions from n/a to 2.9.5. An attacker could exploit this weakness to inject malicious scripts into a victim's web browser and gain unauthorized access to their data or perform unintended actions. Users are advised to apply available patches or upgrades to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share