CVE-2025-57988
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny Toolkit for LearnDash: from n/a through <= 3.7.0.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Uncanny Toolkit for LearnDash allows attackers to inject malicious scripts via improperly neutralized input in WordPress sites.
Stored Cross-Site Scripting (XSS) vulnerability exists in Uncanny Toolkit for LearnDash plugin for WordPress, affecting versions up to and including 3.7.0.3. The vulnerability arises due to improper neutralization of user input during web page generation, known as stored XSS. This means that unsanitized or unescaped input can be stored on the server and later executed in the context of other users' browsers when accessing affected pages [1].
Exploitation requires a privileged user, such as an administrator or editor, to take an action like clicking a malicious link or submitting crafted data. This interaction may be initiated by a third-party attacker by tricking a legitimate privileged user into performing the action. No authentication from the attacker's side is needed beyond triggering the privileged user's session [1].
If successfully exploited, an attacker can inject arbitrary HTML and JavaScript code. This payload may include redirects, advertisements, defacement, or other malicious content that executes when visitors view the affected page. Potential impacts include session hijacking, credential theft, or further compromise of the WordPress site [1].
The vendor has released version 3.7.0.4 which patches the issue. Users are strongly advised to update immediately. Patchstack users may enable auto-updates to receive the fix automatically. This vulnerability is considered low severity by the vendor but may still be targeted in mass-exploit campaigns [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=3.7.0.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.