CVE-2025-60144
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yonifre Lenix scss compiler lenix-scss-compiler allows Stored XSS.This issue affects Lenix scss compiler: from n/a through <= 1.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Lenix SCSS Compiler WordPress plugin up to version 1.2 allows attackers with contributor-level access to inject malicious scripts.
Vulnerability
Overview
The Lenix SCSS Compiler WordPress plugin (lenix-scss-compiler) versions through 1.2 contain a Stored Cross-Site Scripting (XSS) vulnerability. This stems from improper neutralization of user input during web page generation, allowing malicious scripts to be permanently stored on the server [1].
Exploitation
Conditions
The vulnerability requires at least contributor-level user privileges. Exploitation also requires user interaction, such as clicking a malicious link or visiting a crafted page [1]. Attackers can inject arbitrary HTML and JavaScript payloads, which are then executed when other users (including site visitors) access the affected page.
Impact
Successful exploitation enables an attacker to inject redirects, advertisements, or other HTML payloads into the website. These scripts execute in the context of visitors' browsers, potentially leading to defacement, credential theft, or malware distribution [1].
Mitigation
The vendor has not released a patched version for this vulnerability. Since the plugin's last update was version 1.2, users should assume it is end-of-life and consider disabling or removing the plugin immediately. The Patchstack advisory notes that such vulnerabilities are used in mass-exploit campaigns against thousands of websites [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <= 1.2
- Range: <=1.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.