VYPR
High severity7.1NVD Advisory· Published Mar 3, 2025· Updated Apr 23, 2026

CVE-2025-23740

CVE-2025-23740

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zbynek Nedoma Easy School Registration easy-school-registration allows Reflected XSS.This issue affects Easy School Registration: from n/a through <= 3.9.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS vulnerability in Easy School Registration plugin allows script injection via improper input neutralization; patch available.

Vulnerability

Overview CVE-2025-23740 is a reflected Cross-Site Scripting (XSS) vulnerability in the WordPress plugin Easy School Registration, versions up to and including 3.9.8. The root cause is improper neutralization of user input during web page generation, allowing an attacker to inject arbitrary scripts [1].

Exploitation

Details The vulnerability is classified as reflected XSS and requires user interaction. An attacker can craft a malicious link or form that, when clicked or submitted by a victim with appropriate privileges, executes injected script code in the context of the victim's browser [1]. The attack does not require prior authentication for the attacker, but the victim must be authenticated and perform an action.

Impact

Successful exploitation could allow an attacker to inject malicious scripts, such as redirects, advertisements, or other HTML payloads. These scripts execute when other users visit the affected site, potentially leading to session hijacking, defacement, or phishing attacks [1].

Mitigation

Users should immediately update the Easy School Registration plugin to a patched version. As a temporary measure, Patchstack has issued a mitigation rule to block attacks until an official update is deployed [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.