VYPR
Medium severity6.5NVD Advisory· Published Apr 23, 2026· Updated Apr 23, 2026

CVE-2025-62110

CVE-2025-62110

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS.This issue affects Rescue Shortcodes: from n/a through 3.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in Rescue Shortcodes WordPress plugin (versions up to 3.3) allows authenticated attackers with contributor-level access to inject malicious scripts via unsanitized shortcode inputs.

Vulnerability

Overview The Rescue Shortcodes plugin for WordPress versions up to 3.3 suffers from a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This allows malicious shortcode parameters to be stored and later executed in the browsers of visitors.

Exploitation

Details Exploitation requires an authenticated user with at least contributor-level privileges, as shortcodes are typically inserted into posts or pages. The attacker can inject arbitrary JavaScript via a shortcode attribute. When the content is rendered, the script executes without proper sanitization [1]. While user interaction (e.g., clicking a link) may be needed to trigger the injection, the stored payload automatically runs on page load for subsequent visitors.

Impact

Successful exploitation enables an attacker to perform actions such as redirecting users to malicious sites, displaying advertisements, stealing session cookies, or defacing the website. The CVSS score of 6.5 reflects a medium severity, but such vulnerabilities are frequently targeted in mass exploitation campaigns [1].

Mitigation

The vendor has released version 3.4 which resolves the issue. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. No workaround is available [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

1