CVE-2025-68031
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faraz sms افزونه پیامک حرفه ای فراز اس ام اس farazsms allows Reflected XSS.This issue affects افزونه پیامک حرفه ای فراز اس ام اس: from n/a through <= 2.7.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A reflected XSS vulnerability in the farazsms WordPress plugin (≤2.7.3) allows attackers to inject malicious scripts via crafted requests, potentially leading to site compromise.
Vulnerability
Overview The vulnerability is a reflected Cross-Site Scripting (XSS) in the WordPress plugin 'افزونه پیامک حرفه ای فراز اس ام اس' (farazsms) versions up to and including 2.7.3. The plugin fails to properly neutralize user input during web page generation, allowing an attacker to inject arbitrary HTML and JavaScript code into a response [1].
Exploitation
Details Exploitation requires user interaction, such as a privileged user clicking a malicious link or visiting a crafted page. The attacker does not need authentication but must trick a user with sufficient privileges (e.g., admin) into performing an action. This makes the vulnerability suitable for mass-exploit campaigns targeting thousands of WordPress sites [1].
Impact
Successful exploitation enables the attacker to execute malicious scripts in the context of the victim's browser. This can lead to redirects, injection of advertisements, theft of session cookies, or other actions that compromise the site's integrity and user trust [1].
Mitigation
Users are advised to update the plugin to a patched version as soon as possible. Until an official patch is available, Patchstack provides a mitigation rule that blocks attacks. Given the vulnerability's expected exploitation, immediate action is recommended [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.