VYPR
Medium severity5.9NVD Advisory· Published Aug 28, 2025· Updated Apr 23, 2026

CVE-2025-48305

CVE-2025-48305

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vikingjs Goal Tracker for Patreon goal-tracker-for-patreon allows Stored XSS.This issue affects Goal Tracker for Patreon: from n/a through <= 0.4.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in WordPress Goal Tracker for Patreon plugin (≤0.4.6) allows attackers to inject malicious scripts via unsanitized input.

The Goal Tracker for Patreon plugin for WordPress (versions up to and including 0.4.6) contains a stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user input during page generation. This allows an attacker to inject arbitrary web scripts that are stored on the server and executed when other users visit the affected page.

Exploitation of this vulnerability requires a user with at least contributor-level privileges to craft a malicious payload. However, this vulnerability is known to be used in mass-exploit campaigns, targeting thousands of websites regardless of size. User interaction is required from a privileged user to trigger the execution, such as clicking a link or submitting a form [1].

Successful exploitation enables an attacker to execute malicious scripts in the context of a victim's browser. This can lead to redirects, advertisements, and other HTML payloads being displayed to site visitors, potentially compromising the site's integrity and user trust [1].

The vendor has released a fix; users are strongly advised to update the plugin to version 0.4.7 or later. If immediate updating is not possible, a web developer or hosting provider should be consulted for mitigation [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.