VYPR
Medium severity6.5NVD Advisory· Published Jun 27, 2025· Updated Apr 28, 2026

CVE-2025-53320

CVE-2025-53320

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wp Enhanced Free Downloads EDD allows DOM-Based XSS. This issue affects Free Downloads EDD: from n/a through 1.0.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DOM-based Cross-Site Scripting in Free Downloads EDD plugin for WordPress versions up to 1.0.4 allows unauthenticated attackers to inject arbitrary scripts.

Vulnerability

Description

The Free Downloads EDD WordPress plugin, through version 1.0.4, fails to properly neutralize user input during web page generation, leading to a DOM-based Cross-Site Scripting (XSS) vulnerability. This is a classic improper input handling issue where attacker-controlled data is reflected in the page without sanitization [1].

Exploitation

Attackers can exploit this flaw without needing authentication or advanced privileges. The vulnerability is triggered when a victim user (such as a site administrator) interacts with a crafted link, visits a malicious page, or submits a specially designed form. This user interaction is the only prerequisite for successful exploitation [1].

Impact

Successful exploitation allows an attacker to inject arbitrary JavaScript, HTML, or other malicious payloads into the vulnerable site. These scripts execute in the context of the victim's browser when they visit the affected page. Potential consequences include redirects to malicious sites, injection of unwanted advertisements, theft of sensitive session data, or other harmful actions that can compromise both site visitors and administrators [1].

Mitigation

The vendor has not released a patched version, as the plugin is end-of-life (EOL). Users are strongly advised to immediately update the plugin if a newer version exists, or to remove it entirely. If removal is not possible, contacting a hosting provider or web developer for assistance is recommended. This vulnerability is known to be used in mass-exploit campaigns targeting thousands of sites [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.