VYPR
High severity7.1NVD Advisory· Published Mar 3, 2025· Updated Apr 23, 2026

CVE-2025-26563

CVE-2025-26563

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muneeb Mobile rocket-wp-mobile allows Reflected XSS.This issue affects Mobile: from n/a through <= 1.3.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS vulnerability in the Mobile plugin for WordPress (versions ≤1.3.3) allows attackers to inject malicious scripts via unneutralized input.

Vulnerability

Overview

The Mobile plugin for WordPress (rocket-wp-mobile) versions from n/a through 1.3.3 contains a reflected cross-site scripting (XSS) vulnerability. The issue stems from improper neutralization of user-supplied input during web page generation [1]. This reflects the classic failure to sanitize or encode output, enabling script injection.

Exploitation

Conditions

An attacker can exploit this vulnerability by crafting a malicious link or form that, when visited or submitted by a privileged user (such as an administrator), executes arbitrary JavaScript in the context of the victim's session. User interaction is required for successful exploitation [1]. The vulnerability does not require authentication for the initial attack vector but relies on a privileged user performing an action on the crafted payload.

Impact

Successful exploitation could allow an attacker to inject malicious scripts into the affected website. This may result in redirects to external sites, display of advertisements, theft of session cookies, or other unauthorized actions when other users visit the site [1]. The CVSS v3 base score is 7.1 (High).

Mitigation and

Remediation

As of the publication date, an official patch had not been released for the affected versions. The vendor advisory recommends updating the plugin to a patched version as soon as available. In the interim, a mitigation rule from Patchstack can block attacks until a safe update can be applied [1]. Users unable to patch immediately should consult their hosting provider or a web developer for assistance.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.