VYPR
Medium severity6.5NVD Advisory· Published Dec 9, 2025· Updated Apr 15, 2026

CVE-2025-67551

CVE-2025-67551

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wappointment team Wappointment wappointment allows Stored XSS.This issue affects Wappointment: from n/a through <= 2.6.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in Wappointment WordPress plugin allows attackers to inject malicious scripts, requiring user interaction but impacting site visitors.

A stored cross-site scripting (XSS) vulnerability exists in the Wappointment WordPress plugin, versions up to and including 2.6.9. The flaw arises from improper neutralization of user input during web page generation, allowing an attacker to inject arbitrary scripts that are stored and executed in the context of other users' browsers [1].

Exploitation requires a privileged user, such as an administrator, to perform an action like clicking a malicious link or submitting a crafted form. Once triggered, the injected script is stored on the server and executed when any visitor accesses the affected page. This attack vector is commonly used in automated mass-exploit campaigns targeting WordPress sites [1].

A successful attack can lead to injection of malicious scripts, including redirects, advertisements, and other HTML payloads. This compromises the integrity of the website and can affect all visitors, potentially leading to further attacks or data theft [1].

The vulnerability is patched in version 2.7.0. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. As an interim measure, if direct update is not possible, consulting with a hosting provider or web developer is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.