VYPR
High severity7.1NVD Advisory· Published May 19, 2025· Updated Apr 28, 2026

CVE-2025-22792

CVE-2025-22792

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jinwen Js O3 Lite allows Reflected XSS.This issue affects Js O3 Lite: from n/a through 1.5.8.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS vulnerability in WordPress Js O3 Lite theme allows unauthenticated attackers to inject arbitrary scripts via crafted requests.

Vulnerability

Details

CVE-2025-22792 is a reflected Cross-Site Scripting (XSS) vulnerability in the Js O3 Lite WordPress theme, affecting versions from n/a through 1.5.8.2. The issue stems from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject malicious scripts into a response that is immediately reflected back to the user [1].

Exploitation

The vulnerability is classified as reflected XSS, meaning the attacker must trick a victim into clicking a specially crafted link. No authentication is required for the attacker to generate the malicious URL, but successful exploitation requires the victim to interact with the link (e.g., clicking it while logged into the WordPress site). This interaction can be initiated by any user, including those with elevated privileges [1].

Impact

If exploited, an attacker can execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, defacement, redirection to malicious sites, or injection of advertisements and other HTML payloads. The CVSS v3 score of 7.1 (High) reflects the potential for significant harm, especially given that such vulnerabilities are commonly used in mass-exploit campaigns targeting thousands of websites [1].

Mitigation

As of the publication date, no official patch has been released for the Js O3 Lite theme. Users are advised to update the theme as soon as a patched version becomes available. In the interim, Patchstack has provided a virtual mitigation rule to block attacks. Website administrators should also consider implementing web application firewall rules or disabling the theme until a fix is applied [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.