Cyber Posture

CVE-2025-22680

High

Published: 16 February 2025

Published
16 February 2025
Modified
28 April 2026
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0009 25.0th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ad Inserter Pro allows Reflected XSS. This issue affects Ad Inserter Pro: from n/a through 2.7.39.

Security Summary

CVE-2025-22680 is an Improper Neutralization of Input During Web Page Generation vulnerability, enabling Reflected Cross-site Scripting (XSS) as classified under CWE-79. It affects the Ad Inserter Pro WordPress plugin, specifically versions from n/a through 2.7.39. Published on 2025-02-16, the issue carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), indicating high severity due to network accessibility, low complexity, no required privileges, user interaction, and changed scope with low impacts on confidentiality, integrity, and availability.

Attackers can exploit this vulnerability remotely without authentication by tricking users into interacting with maliciously crafted links or inputs that reflect executable scripts back in the browser. No special privileges are needed, making it accessible to any unauthenticated adversary on the network. Successful exploitation allows injection of arbitrary JavaScript, potentially leading to session hijacking, data theft, or further site compromise within the victim's browser context, though impacts remain low per the CVSS metrics.

The Patchstack advisory (https://patchstack.com/database/wordpress/plugin/ad-inserter-pro/vulnerability/wordpress-ad-inserter-pro-plugin-2-7-39-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve) details the vulnerability in Ad Inserter Pro version 2.7.39, recommending mitigation through updating to a patched version beyond 2.7.39.

Details

CWE(s)
CWE-79

References