VYPR
High severity7.1NVD Advisory· Published Feb 20, 2026· Updated Apr 15, 2026

CVE-2025-68031

CVE-2025-68031

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faraz sms افزونه پیامک حرفه ای فراز اس ام اس farazsms allows Reflected XSS.This issue affects افزونه پیامک حرفه ای فراز اس ام اس: from n/a through <= 2.7.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A reflected XSS vulnerability in the farazsms WordPress plugin (≤2.7.3) allows attackers to inject malicious scripts via crafted requests, potentially leading to site compromise.

Vulnerability

Overview The vulnerability is a reflected Cross-Site Scripting (XSS) in the WordPress plugin 'افزونه پیامک حرفه ای فراز اس ام اس' (farazsms) versions up to and including 2.7.3. The plugin fails to properly neutralize user input during web page generation, allowing an attacker to inject arbitrary HTML and JavaScript code into a response [1].

Exploitation

Details Exploitation requires user interaction, such as a privileged user clicking a malicious link or visiting a crafted page. The attacker does not need authentication but must trick a user with sufficient privileges (e.g., admin) into performing an action. This makes the vulnerability suitable for mass-exploit campaigns targeting thousands of WordPress sites [1].

Impact

Successful exploitation enables the attacker to execute malicious scripts in the context of the victim's browser. This can lead to redirects, injection of advertisements, theft of session cookies, or other actions that compromise the site's integrity and user trust [1].

Mitigation

Users are advised to update the plugin to a patched version as soon as possible. Until an official patch is available, Patchstack provides a mitigation rule that blocks attacks. Given the vulnerability's expected exploitation, immediate action is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.