VYPR
Medium severity6.5NVD Advisory· Published Nov 21, 2025· Updated Apr 15, 2026

CVE-2025-66053

CVE-2025-66053

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfold allows Stored XSS.This issue affects Enfold: from n/a through <= 7.1.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Enfold theme ≤7.1.2 allows attackers to inject malicious scripts via improperly neutralized input, patched in 7.1.3.

An Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as Stored Cross-Site Scripting (XSS), exists in the Kriesi Enfold theme for WordPress. The issue affects all versions of the theme through 7.1.2 [1]. The root cause is insufficient sanitization of user-supplied input that is later rendered in web pages, allowing an attacker to store arbitrary HTML and JavaScript [1].

To exploit this vulnerability, an attacker must have a role capable of submitting input (e.g., author or editor). The attack requires user interaction — a privileged user must perform an action such as clicking a malicious link or visiting a crafted page [1]. Once the malicious script is stored, it executes automatically when other users or visitors view the affected page [1].

Successful exploitation could allow an attacker to inject malicious scripts, including redirects, advertisements, and other HTML payloads. These scripts would run in the context of a visitor's browser, potentially leading to data theft, session hijacking, or defacement [1]. The CVSS v3 score is 6.5 (Medium), indicating moderate impact [1].

The vulnerability is remediated in Enfold version 7.1.3. Users are strongly advised to update their theme to this version immediately [1]. For those unable to update, consulting a hosting provider or web developer is recommended. The vendor rates this issue as low severity; however, XSS vulnerabilities are commonly exploited in mass campaigns [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.