VYPR
Medium severity5.9NVD Advisory· Published May 7, 2025· Updated Apr 23, 2026

CVE-2025-47638

CVE-2025-47638

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarvesh M Rao WP Discord Invite wp-discord-invite allows Stored XSS.This issue affects WP Discord Invite: from n/a through <= 2.5.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in WP Discord Invite plugin (≤2.5.3) allows authenticated attackers to inject malicious scripts viewed by site visitors.

Vulnerability

Overview

The WP Discord Invite plugin for WordPress (versions up to and including 2.5.3) contains a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This CWE-79 flaw enables an authenticated user to inject arbitrary JavaScript or HTML payloads that persist in the application, affecting subsequent visitors.

Exploitation

Details

Exploitation requires a privileged user who can submit or save data processed by the plugin. An attacker with contributor-level access or higher can inject malicious script content into fields that are later rendered without sanitization [1]. While the vulnerability demands some user interaction from the target (e.g., clicking a malicious link or visiting a crafted page), the stored nature means any site visitor may be impacted once the payload is saved [1].

Potential

Impact

Successful exploitation allows an attacker to execute arbitrary scripts in the context of the victim's browser session. This could be used to steal session cookies, perform actions on behalf of the authenticated user, deface the page, or inject unwanted advertisements and redirects [1]. The impact is generally limited to browser-level attacks within the WordPress site.

Mitigation and

Remediation

The vendor has released version 2.6.0 which addresses the vulnerability [1]. Users are strongly advised to update immediately. For those unable to update, consulting a hosting provider or web developer for temporary workarounds is recommended. Patchstack users can enable auto-updates for this plugin to ensure prompt patching [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

1
v2.6.0

Release: wp-discord-invite 2.6.0 (next version after vulnerable 2.5.3)

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.