CVE-2025-25165

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 3, 2025
CWE ID 79

Summary

CVE-2025-25165 is a Cross-site Scripting (XSS) vulnerability affecting the NotFound Staff Directory Plugin: Company Directory. The plugin, which is used for creating and managing staff directories, is susceptible to stored XSS attacks. An attacker can inject malicious scripts into the web page, allowing them to execute arbitrary code in the context of the affected user. This issue has the potential to lead to serious security consequences, including data theft and unauthorized access. The vulnerability affects all versions of the plugin from n/a through 4.3. It is recommended that users upgrade to the latest version or disable the plugin until a patch is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share