VYPR
High severity7.1NVD Advisory· Published Mar 3, 2025· Updated Apr 23, 2026

CVE-2025-23741

CVE-2025-23741

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian Chaillou Notifications Center notifications-center allows Reflected XSS.This issue affects Notifications Center: from n/a through <= 1.5.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in WordPress Notifications Center plugin ≤1.5.2 allows attackers to inject malicious scripts via improperly neutralized input.

Vulnerability

Description The Notifications Center plugin for WordPress, versions up to and including 1.5.2, contains a reflected cross-site scripting (XSS) vulnerability. The root cause is improper neutralization of user input during web page generation. This allows an attacker to inject arbitrary HTML or JavaScript code into the response page.

Exploitation

Details Exploitation requires user interaction. A privileged user (such as an administrator) must click a malicious link, visit a crafted page, or submit a specially formed form that triggers the vulnerability. The attacker does not need prior authentication to the WordPress site but relies on tricking an authenticated user into performing an action [1].

Impact

Successful exploitation could allow a malicious actor to inject scripts that execute in the context of the victim's browser session. This can be used to perform actions like redirecting visitors, displaying advertisements, or stealing session cookies. The vulnerability is considered moderately dangerous and is expected to be included in mass-exploit campaigns targeting thousands of websites [1].

Mitigation

The plugin vendor advises an immediate update. Users unable to update should contact their hosting provider or web developer for alternative protections, such as applying a virtual patch [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.