VYPR
Medium severity5.9NVD Advisory· Published Dec 16, 2025· Updated Apr 27, 2026

CVE-2025-67986

CVE-2025-67986

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows DOM-Based XSS.This issue affects Document Library Lite: from n/a through <= 1.1.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DOM-based XSS in WordPress Document Library Lite plugin (<=1.1.7) allows script injection; update to 1.2.0.

CVE-2025-67986 is a DOM-based Cross-site Scripting (XSS) vulnerability in the Barn2 Plugins Document Library Lite plugin for WordPress, affecting versions up to and including 1.1.7. The plugin fails to properly neutralize input during web page generation, allowing an attacker to inject malicious scripts into the DOM [1].

Exploitation requires user interaction, typically a privileged user such as an administrator clicking a crafted link or visiting a specially prepared page [1]. This interaction triggers the injected script to execute in the context of the victim's browser.

Successful exploitation could allow an attacker to inject arbitrary scripts, resulting in actions like redirecting visitors to malicious sites, displaying advertisements, or stealing sensitive data. Such vulnerabilities are often targeted in mass-exploit campaigns [1].

The issue is resolved in version 1.2.0 of the plugin. Users are strongly advised to update immediately. For Patchstack users, enabling auto-updates for vulnerable plugins is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.