VYPR
High severity7.1NVD Advisory· Published Mar 3, 2025· Updated Apr 23, 2026

CVE-2025-23883

CVE-2025-23883

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in unalignedcoder Stray Random Quotes stray-quotes allows Reflected XSS.This issue affects Stray Random Quotes: from n/a through <= 1.9.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stray Random Quotes WordPress plugin <=1.9.9 is vulnerable to reflected XSS, allowing script injection via unvalidated input.

Vulnerability

Overview The Stray Random Quotes plugin for WordPress, in versions up to and including 1.9.9, contains a reflected Cross-Site Scripting (XSS) vulnerability. The root cause is the improper neutralization of user-supplied input during web page generation, as described in the official CVE entry. This flaw is classified as High severity with a CVSS v3 base score of 7.1 [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.