VYPR
Medium severity5.9NVD Advisory· Published Aug 14, 2025· Updated Apr 23, 2026

CVE-2025-55713

CVE-2025-55713

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq Blocksy blocksy allows Stored XSS.This issue affects Blocksy: from n/a through <= 2.1.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stored XSS vulnerability in the Blocksy WordPress theme allows attackers to inject malicious scripts via unsanitized input, affecting versions up to 2.1.6.

Vulnerability

CVE-2025-55713 is a stored Cross-Site Scripting (XSS) vulnerability in the Blocksy WordPress theme by creativethemeshq. The flaw arises from improper neutralization of user-supplied input during web page generation [1]. This allows an authenticated attacker with elevated privileges (such as a shop manager or administrator) to inject arbitrary HTML or JavaScript code that is stored on the server and later executed when other users, including visitors, access the affected page.

Exploitation

Exploitation requires an authenticated user with the necessary permissions to save content (e.g., theme options, widgets, or posts) that is processed by the vulnerable theme code. The attacker then injects a malicious payload, such as a script tag, which the theme fails to sanitize or escape [1]. No direct user interaction (e.g., clicking a link) is needed for the stored payload to execute; simply visiting the compromised page triggers the script in the victim's browser.

Impact

A successful attack could allow the attacker to perform actions such as redirecting visitors to malicious sites, displaying advertisements, stealing session cookies, or defacing the website. While the CVSS score of 5.9 (Medium) indicates a relatively lower severity, the vulnerability may be targeted in automated mass-exploit campaigns against numerous WordPress sites [1].

Mitigation

The vendor has released version 2.1.7, which resolves the issue by properly sanitizing or escaping the vulnerable input fields. Users are strongly advised to update the Blocksy theme to version 2.1.7 or later [1]. If an immediate update is not possible, it is recommended to limit the number of privileged users and review all custom content for potential malicious code.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.