VYPR
Medium severity5.9NVD Advisory· Published Sep 26, 2025· Updated Apr 23, 2026

CVE-2025-60101

CVE-2025-60101

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duongancol Woostify woostify allows Stored XSS.This issue affects Woostify: from n/a through <= 2.4.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stored Cross-Site Scripting vulnerability in the Woostify WordPress theme up to version 2.4.2 allows authenticated attackers to inject malicious scripts into web pages.

Vulnerability

Overview

The Woostify WordPress theme, versions 2.4.2 and earlier, contains a stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This flaw enables attackers with required privileges to inject arbitrary JavaScript code that persists on the server and executes in the browsers of site visitors [1].

Exploitation

Requirements

Exploitation requires a privileged user role with the ability to submit or modify content fields that are inadequately sanitized by the theme [1]. While the vulnerability can be initiated by such an attacker, successful execution demands an action from another privileged user — such as clicking a malicious link, submitting a form, or visiting a crafted page — to trigger the stored payload [1].

Impact and

Risk

An attacker exploiting this vulnerability can inject malicious scripts into the site, leading to potential redirects, unauthorized advertisements, or other HTML payloads that execute when visitors access the compromised pages [1]. This could compromise visitor data or tarnish site reputation, and such XSS flaws are commonly used in mass-exploit campaigns targeting WordPress sites regardless of their size [1].

Mitigation

The vendor has indicated that the Woostify theme is unlikely to receive further updates or patches, and simply deactivating the theme does not remove the security threat unless a mitigation rule (e.g., from Patchstack) is deployed [1]. The recommended action is to remove and replace the theme entirely [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.