VYPR
High severity7.1NVD Advisory· Published Apr 24, 2025· Updated Apr 23, 2026

CVE-2025-39408

CVE-2025-39408

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress BruteGuard – Brute Force Login Protection bruteguard allows Reflected XSS.This issue affects BruteGuard – Brute Force Login Protection: from n/a through <= 0.1.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

BruteGuard 0.1.4 and earlier are vulnerable to reflected XSS via improper input sanitization, enabling script injection through crafted requests.

The BruteGuard – Brute Force Login Protection plugin for WordPress versions 0.1.4 and below fails to properly neutralize user-supplied input during web page generation, leading to a reflected Cross-Site Scripting (XSS) vulnerability [1]. The root cause is a lack of sufficient sanitization or escaping of input that is reflected back to the user in the response.

An attacker can exploit this flaw by crafting a malicious link or form submission that, when interacted with by a privileged user (e.g., an administrator), injects arbitrary JavaScript into the page context [1]. The attack does not require direct site access, but relies on social engineering to lure the target user into clicking the crafted URL or submitting the form. No authentication is needed to trigger the reflection, but successful execution depends on a privileged user performing the action.

If exploited, an attacker can inject malicious scripts capable of redirecting visitors, displaying advertisements, or delivering other arbitrary HTML payloads [1]. This could compromise site integrity, lead to data exposure, or facilitate further attacks on site visitors. The CVSS score of 7.1 reflects the moderate to high severity, and the vulnerability is expected to be targeted in mass-exploit campaigns.

As of the publication date, no official patch has been released for BruteGuard; users are advised to apply a mitigation rule via a security plugin such as Patchstack until an update is available [1]. Immediate action is recommended to update the plugin or seek assistance from hosting providers to mitigate the risk.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.