VYPR
Medium severity6.5NVD Advisory· Published Dec 9, 2025· Updated Apr 15, 2026

CVE-2025-67550

CVE-2025-67550

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rhewlif Donation Thermometer donation-thermometer allows Stored XSS.This issue affects Donation Thermometer: from n/a through <= 2.2.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stored XSS vulnerability in the Donation Thermometer plugin ≤2.2.6 lets attackers inject malicious scripts via improper input neutralization.

The Donation Thermometer plugin for WordPress, versions 2.2.6 and earlier, contains a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This flaw allows an attacker with a low-privileged role (such as a subscriber) to inject arbitrary JavaScript or HTML into the plugin's output, which is then stored and executed in the context of any visitor's browser [1].

Exploitation requires a privileged user to perform an action, such as visiting a crafted page or submitting a form [1]. However, once the malicious payload is stored, it automatically executes when other users load the affected page, making the attack effective even without direct interaction from the victim [1].

Successful exploitation enables an attacker to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into the website [1]. These scripts execute in the browser of every visitor, potentially leading to data theft, defacement, or further compromise of the site and its users [1].

The vendor has released version 2.2.7 which resolves the vulnerability by properly sanitizing user input [1]. Users are strongly advised to update immediately or enable auto-updates if using Patchstack. While the issue is rated as medium severity (CVSS 6.5), prompt remediation is recommended to prevent exploitation in mass campaigns targeting thousands of WordPress sites [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.