VYPR
Medium severity6.5NVD Advisory· Published Dec 31, 2025· Updated Apr 23, 2026

CVE-2025-63000

CVE-2025-63000

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpforchurch Sermon Manager sermon-manager-for-wordpress allows Stored XSS.This issue affects Sermon Manager: from n/a through <= 2.30.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Sermon Manager for WordPress up to 2.30.0 allows attackers with contributor+ roles to inject malicious scripts that execute when visitors view affected pages.

Vulnerability

Overview

CVE-2025-63000 is a stored cross-site scripting (XSS) vulnerability in the Sermon Manager plugin for WordPress (sermon-manager-for-wordpress), affecting all versions through 2.30.0 [1]. The flaw originates from improper neutralization of user-supplied input during web page generation, allowing malicious script content to be permanently stored on the server and executed in the browsers of site visitors [1].

Exploitation

Requirements

Exploitation requires an authenticated user with at least Contributor-level privileges (the 'Required Privilege' level noted in the advisory) [1]. The attacker must then craft a payload containing malicious JavaScript, HTML, or other client-side code and inject it into a vulnerable field within the plugin's interface [1]. Because the injected scripts are stored on the server and later triggered when any user—including administrators or visitors—views the affected page, without requiring social engineering toward the victim [1].

Impact

A successful attack enables the adversary to execute arbitrary scripts in the context of the victim's browser session [1]. This can be used to steal session cookies, redirect users to phishing or malware-hosting sites, deface the website, or inject advertisements and other unwanted HTML content [1]. Because the script persists in the database, the attack can affect many users over time until the malicious content is removed or the plugin is secured.

Mitigation

The vendor has addressed this vulnerability in version 2.30.1 or later [1]. Users running Sermon Manager 2.30.0 or any earlier version are advised to update immediately [1]. For sites where immediate updating immediately, consider disabling the plugin, restricting contributor-level roles, or asking a web developer to apply input sanitization until the patch can be deployed [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.