CVE-2025-22583
Published: 13 January 2025
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anshulsojatia Scan External Links scan-external-links allows Reflected XSS.This issue affects Scan External Links: from n/a through <= 1.0.
Security Summary
CVE-2025-22583 is an Improper Neutralization of Input During Web Page Generation vulnerability, enabling Reflected Cross-site Scripting (XSS) as classified under CWE-79. It affects the WordPress plugin Scan External Links developed by anshulsojatia, with the issue present in all versions from n/a through 1.0 inclusive. Published on 2025-01-13T14:15:12.300, the vulnerability carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
Unauthenticated attackers accessible over the network can exploit this vulnerability with low attack complexity by tricking users into interacting with malicious input, such as clicking a crafted link. Successful exploitation allows execution of arbitrary JavaScript in the context of the victim's browser, potentially compromising low levels of confidentiality, integrity, and availability due to the changed scope.
Mitigation details are available in the Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/scan-external-links/vulnerability/wordpress-scan-external-links-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve.
Details
- CWE(s)