CVE-2025-67550
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rhewlif Donation Thermometer donation-thermometer allows Stored XSS.This issue affects Donation Thermometer: from n/a through <= 2.2.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stored XSS vulnerability in the Donation Thermometer plugin ≤2.2.6 lets attackers inject malicious scripts via improper input neutralization.
The Donation Thermometer plugin for WordPress, versions 2.2.6 and earlier, contains a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This flaw allows an attacker with a low-privileged role (such as a subscriber) to inject arbitrary JavaScript or HTML into the plugin's output, which is then stored and executed in the context of any visitor's browser [1].
Exploitation requires a privileged user to perform an action, such as visiting a crafted page or submitting a form [1]. However, once the malicious payload is stored, it automatically executes when other users load the affected page, making the attack effective even without direct interaction from the victim [1].
Successful exploitation enables an attacker to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into the website [1]. These scripts execute in the browser of every visitor, potentially leading to data theft, defacement, or further compromise of the site and its users [1].
The vendor has released version 2.2.7 which resolves the vulnerability by properly sanitizing user input [1]. Users are strongly advised to update immediately or enable auto-updates if using Patchstack. While the issue is rated as medium severity (CVSS 6.5), prompt remediation is recommended to prevent exploitation in mass campaigns targeting thousands of WordPress sites [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2.2.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.