VYPR
Medium severity6.5NVD Advisory· Published Sep 26, 2025· Updated Apr 23, 2026

CVE-2025-60138

CVE-2025-60138

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a through <= 2.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in SKT Blocks WordPress plugin allows authenticated attackers to inject malicious scripts, affecting versions up to 2.6.

The SKT Blocks plugin for WordPress suffers from a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This flaw allows an attacker with the required privileges to inject arbitrary HTML and JavaScript code that is stored on the server and executed when other users visit the affected page.

Exploitation requires an authenticated user with the appropriate role to perform an action, such as clicking a malicious link or submitting a crafted form [1]. The vulnerability is particularly concerning because it is used in mass-exploit campaigns targeting thousands of websites, regardless of their size or popularity [1].

Successful exploitation enables an attacker to inject malicious scripts, including redirects, advertisements, and other HTML payloads, which are executed in the context of the victim's browser when they access the compromised page [1]. This can lead to defacement, data theft, or further compromise of the site.

As an immediate mitigation, users should update the SKT Blocks plugin to a version newer than 2.6 [1]. If updating is not possible, it is recommended to contact the hosting provider or a web developer for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.