VYPR
Medium severity6.5NVD Advisory· Published Nov 21, 2025· Updated Apr 15, 2026

CVE-2025-66091

CVE-2025-66091

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Design Stylish Cost Calculator stylish-cost-calculator allows DOM-Based XSS.This issue affects Stylish Cost Calculator: from n/a through <= 8.1.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DOM-Based XSS vulnerability in Stylish Cost Calculator plugin (≤8.1.5) allows attackers to inject malicious scripts via unneutralized input.

The Stylish Cost Calculator plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input during web page generation [1]. This flaw exists in versions up to and including 8.1.5, where the plugin fails to adequately sanitize or escape input before outputting it in the DOM.

Exploitation requires user interaction, such as a privileged user clicking a malicious link or visiting a crafted page [1]. This means an attacker would need to trick a user with elevated privileges (e.g., an administrator) into performing an action that triggers the vulnerability. Once triggered, the malicious script executes within the context of the user's browser session.

Successful exploitation allows an attacker to inject arbitrary scripts, which can be used to redirect visitors to malicious sites, display advertisements, or deliver other HTML payloads [1]. When other guests visit the affected page, the injected script executes, potentially leading to further compromise or data theft.

Mitigation is straightforward: update the plugin to version 8.1.6 or later, which resolves the vulnerability [1]. Users are advised to apply the update immediately to protect their sites from potential attacks.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.