VYPR
Medium severity5.9NVD Advisory· Published Dec 9, 2025· Updated Apr 28, 2026

CVE-2025-67555

CVE-2025-67555

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in useStrict UseStrict's Calendly Embedder cal-embedder-lite allows Stored XSS.This issue affects UseStrict's Calendly Embedder: from n/a through <= 1.1.7.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in WordPress UseStrict's Calendly Embedder plugin (<=1.1.7.2) allows attackers to inject malicious scripts, requiring user interaction.

Vulnerability

Description A stored cross-site scripting (XSS) vulnerability exists in UseStrict's Calendly Embedder plugin for WordPress, versions through 1.1.7.2. The plugin fails to properly neutralize input during web page generation, allowing attackers to inject arbitrary HTML and JavaScript. This vulnerability is categorized as CWE-79 (Improper Neutralization of Input During Web Page Generation) [1].

Exploitation

Prerequisites Exploitation requires a privileged user, such as an administrator, to perform an action like clicking a malicious link or submitting a crafted form. The attacker must have contributor-level access or higher to inject the payload, which then becomes stored and executed when other users visit affected pages. The CVSS v3 base score is 5.9, reflecting medium severity [1].

Impact

Successful exploitation enables an attacker to execute malicious scripts in the context of a victim's browser. This can lead to session hijacking, redirection to malicious sites, defacement, or theft of sensitive information. The vulnerability is reportedly used in mass-exploit campaigns targeting thousands of WordPress sites [1].

Mitigation

The plugin vendor has released version 1.2 which resolves the issue. Users are strongly advised to update immediately. Those unable to update should contact their hosting provider or web developer for assistance. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.