VYPR
High severity7.1NVD Advisory· Published Jun 27, 2025· Updated Apr 23, 2026

CVE-2025-52727

CVE-2025-52727

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Vertical Web Pricing Tables css3_vertical_web_pricing_tables allows Reflected XSS.This issue affects CSS3 Vertical Web Pricing Tables: from n/a through <= 1.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A reflected XSS vulnerability in the CSS3 Vertical Web Pricing Tables plugin for WordPress allows unauthenticated attackers to inject malicious scripts via crafted requests.

The CSS3 Vertical Web Pricing Tables plugin for WordPress suffers from a reflected cross-site scripting (XSS) vulnerability. The root cause is the improper neutralization of user input during web page generation, specifically within the css3_vertical_web_pricing_tables plugin. This flaw affects all versions up to and including 1.9, and is classified as a reflected XSS issue [1].

Exploitation of this vulnerability requires user interaction. An attacker must trick a privileged user, such as a site administrator, into clicking a crafted link or visiting a specially prepared page. No authentication is needed to deliver the malicious payload, but the target user must perform an action like clicking a link to trigger the script [1].

An attacker who successfully exploits this flaw can inject arbitrary HTML and JavaScript code into the affected site's pages. This could be used to execute redirects, display unauthorized advertisements, steal session cookies, or perform other malicious actions when regular site visitors access the compromised page [1].

The vulnerability is considered moderate in severity (CVSS 7.1) and is expected to be targeted in mass exploitation campaigns. The vendor has released version 2.0 of the plugin, which fixes the issue. Users are strongly advised to update to version 2.0 or later. For those unable to update immediately, Patchstack offers a virtual patching rule to block exploitation attempts [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.