VYPR
High severity7.1NVD Advisory· Published Jan 8, 2026· Updated Apr 27, 2026

CVE-2025-67932

CVE-2025-67932

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes Listeo Core listeo-core allows Reflected XSS.This issue affects Listeo Core: from n/a through < 2.0.19.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS vulnerability in Listeo Core plugin for WordPress versions before 2.0.19 allows attackers to inject malicious scripts via improper input neutralization.

The vulnerability is a reflected Cross-Site Scripting (XSS) in the WordPress plugin Listeo Core, versions prior to 2.0.19. It stems from improper neutralization of user input during web page generation, allowing an attacker to inject arbitrary HTML and JavaScript into the response [1].

Exploitation requires user interaction, such as clicking a malicious link or visiting a crafted page. An attacker does not need authentication beyond a privileged role to initiate the attack, but the victim (a privileged user) must perform an action for the payload to execute [1].

Successful exploitation could allow the attacker to inject malicious scripts, redirects, advertisements, or other HTML payloads. These scripts would execute in the context of the victim's browser when visiting the affected site, potentially leading to further compromise [1].

The vulnerability is patched in version 2.0.19. Users are advised to update immediately. Patchstack offers a mitigation rule to block attacks until the update is applied [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.