CVE-2025-23600 Information

Description

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in pinal.shah Send to a Friend Addon allows Reflected XSS. This issue affects Send to a Friend Addon: from n/a through 1.4.1.

Reference

https://patchstack.com/database/wordpress/plugin/send-booking-invites-to-friends/vulnerability/wordpress-send-to-a-friend-addon-plugin-1-4-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve

Share on: