VYPR
Medium severity5.9NVD Advisory· Published Aug 20, 2025· Updated Apr 23, 2026

CVE-2025-49412

CVE-2025-49412

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in numixtech Page Transition page-transition allows Stored XSS.This issue affects Page Transition: from n/a through <= 1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in the WordPress Page Transition plugin up to version 1.3 allows authenticated attackers to inject arbitrary scripts.

Vulnerability

Overview

The WordPress Page Transition plugin (versions <= 1.3) contains a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation [1]. This flaw enables authenticated attackers, such as authors or editors, to inject malicious scripts that are permanently stored on the server and executed when any user visits the affected page [1].

Exploitation

Prerequisites

Exploitation requires a user with the appropriate role (e.g., administrator or editor) to perform an action such as clicking a crafted link or submitting a specially prepared form [1]. The attack does not rely on high traffic or site popularity, making it suitable for mass campaigns targeting thousands of WordPress installations [1].

Impact

If successfully exploited, an attacker can inject arbitrary HTML or JavaScript payloads, including redirects, advertisements, or other malicious content [1]. These scripts execute in the browsers of visitors, potentially leading to data theft, phishing, or further compromise of the site [1].

Mitigation

The vendor has not released a fix for this vulnerability; the plugin appears to be abandoned or end-of-life [1]. Users are strongly advised to remove or replace the plugin immediately. As an interim measure, consult a hosting provider or web developer for guidance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.