VYPR
High severity7.1NVD Advisory· Published May 23, 2025· Updated Apr 23, 2026

CVE-2025-47680

CVE-2025-47680

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-tidy-tags xili-tidy-tags allows Reflected XSS.This issue affects xili-tidy-tags: from n/a through <= 1.12.06.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in xili-tidy-tags WordPress plugin ≤1.12.06 allows attackers to inject malicious scripts via unneutralized input.

The xili-tidy-tags plugin for WordPress is vulnerable to reflected cross-site scripting (XSS) due to improper neutralization of user-supplied input during web page generation. This affects versions from n/a through 1.12.06. The vulnerability occurs when the plugin fails to sanitize or escape input before including it in a page output, enabling an attacker to inject arbitrary HTML or JavaScript code.

Exploitation requires user interaction, such as clicking a crafted link or visiting a specially prepared page. No authentication is required, making it accessible to any unauthenticated attacker. The attack surface is typical for reflected XSS: the malicious payload is delivered via a URL parameter and executed in the context of the victim's browser.

Successful exploitation allows an attacker to execute arbitrary scripts in the victim's browser, potentially leading to redirects, ad injection, data theft, or other malicious actions. The CVSS score of 7.1 (High) reflects the moderate impact and ease of exploitation.

The vulnerability has been patched by the vendor. Users are strongly advised to update to a safe version. For those unable to update immediately, Patchstack offers a virtual patch to block exploitation attempts [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.