VYPR
High severity7.1NVD Advisory· Published Dec 18, 2025· Updated Apr 15, 2026

CVE-2025-64221

CVE-2025-64221

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Reflected XSS.This issue affects Reservation Plugin: from n/a through <= 1.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS vulnerability in WordPress Reservation Plugin dt-reservation-plugin allows attackers to inject malicious scripts via crafted requests.

Vulnerability

Overview

The Reservation Plugin (dt-reservation-plugin) for WordPress contains a reflected Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This flaw affects all versions up to and including 1.6, and is classified as High severity with a CVSS v3 score of 7.1.

Exploitation

Details

Exploitation requires user interaction, such as clicking a specially crafted link or visiting a malicious page [1]. An attacker can inject arbitrary HTML and JavaScript payloads into the response, which are then executed in the context of the victim's browser session. No authentication is needed to trigger the vulnerability, but a privileged user must perform the action for successful exploitation.

Impact

Successful exploitation allows an attacker to execute malicious scripts, potentially leading to redirects, advertisements, or other HTML payloads being displayed to site visitors [1]. This could be used for phishing, defacement, or further compromise of the WordPress installation.

Mitigation

The vendor has released version 1.7 which resolves the vulnerability [1]. Users are strongly advised to update immediately. For those unable to update, Patchstack offers a mitigation rule to block attacks until the patch is applied [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.