cvemon logocvemon logo

Activity

Trending

CVEs

CVE-2025-23657

Published Feb 14, 2025

Last updated 7 days ago

  1. Overview

  2. Weaknesses

  3. Social media

  4. References

Overview

Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RusAlex WordPress-to-candidate for Salesforce CRM salesforce-wordpress-to-candidate allows Reflected XSS.This issue affects WordPress-to-candidate for Salesforce CRM: from n/a through <= 1.0.1.
Source
audit@patchstack.com
NVD status
Awaiting Analysis

Weaknesses

audit@patchstack.com
CWE-79

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2025-23657 🔴 HIGH (7.1) 🏢 NotFound - WordPress-to-candidate for Salesforce CRM 🏗️ Unknown Version 🔗 https://t.co/ZqSsfunp3p #CyberCron #VulnAlert https://t.co/n7uDm3xd07

    @cybercronai

    16 Feb 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-23657 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WordPress-to-candidate for Salesforce CRM allows Reflec… https://t.co/t4jWRAyzKl

    @CVEnew

    14 Feb 2025

    176 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-23657
  • https://patchstack.com/database/Wordpress/Plugin/salesforce-wordpress-to-candidate/vulnerability/wordpress-wordpress-to-candidate-for-salesforce-crm-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve
TRY INTRUDER
Intruder logo

© 2026 Intruder Systems Ltd.

AboutPrivacySitemapFeeds