CVE-2025-67986
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows DOM-Based XSS.This issue affects Document Library Lite: from n/a through <= 1.1.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
DOM-based XSS in WordPress Document Library Lite plugin (<=1.1.7) allows script injection; update to 1.2.0.
CVE-2025-67986 is a DOM-based Cross-site Scripting (XSS) vulnerability in the Barn2 Plugins Document Library Lite plugin for WordPress, affecting versions up to and including 1.1.7. The plugin fails to properly neutralize input during web page generation, allowing an attacker to inject malicious scripts into the DOM [1].
Exploitation requires user interaction, typically a privileged user such as an administrator clicking a crafted link or visiting a specially prepared page [1]. This interaction triggers the injected script to execute in the context of the victim's browser.
Successful exploitation could allow an attacker to inject arbitrary scripts, resulting in actions like redirecting visitors to malicious sites, displaying advertisements, or stealing sensitive data. Such vulnerabilities are often targeted in mass-exploit campaigns [1].
The issue is resolved in version 1.2.0 of the plugin. Users are strongly advised to update immediately. For Patchstack users, enabling auto-updates for vulnerable plugins is recommended [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=1.1.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.