VYPR
High severity7.1NVD Advisory· Published Jan 27, 2025· Updated Apr 23, 2026

CVE-2025-23574

CVE-2025-23574

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonathan Lau CubePM cubepm allows Reflected XSS.This issue affects CubePM: from n/a through <= 1.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS vulnerability in CubePM WordPress plugin allows attackers to inject malicious scripts via user interaction.

CubePM WordPress plugin versions ≤ 1.0 suffer from a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user input during web page generation [1]. This allows an attacker to inject arbitrary HTML and JavaScript into a web page, which is then executed in the context of the victim's browser.

Exploitation requires user interaction, such as clicking a specially crafted link or visiting a malicious page. The attacker does not need authentication, but the victim must be a logged-in user or have some privileged role for certain actions [1].

Successful exploitation can lead to script execution that may steal sensitive data, perform actions on behalf of the victim, redirect users to malicious sites, or serve advertisements [1].

As of the advisory, the vendor has not released a patch. Patchstack has provided a mitigation rule to block attacks until an official fix is available. Users are advised to update the plugin when a patch is released or apply the mitigation rule [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.