VYPR
Medium severity6.5NVD Advisory· Published Dec 16, 2025· Updated Apr 15, 2026

CVE-2025-68080

CVE-2025-68080

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal User Avatar - Reloaded user-avatar-reloaded allows Stored XSS.This issue affects User Avatar - Reloaded: from n/a through <= 1.2.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in the User Avatar - Reloaded WordPress plugin (≤1.2.2) lets attackers inject arbitrary scripts, visible to all visitors.

The User Avatar - Reloaded plugin for WordPress (versions 1.2.2 and earlier) contains a stored cross-site scripting (XSS) vulnerability. The root cause is improper neutralization of user-supplied input during web page generation, allowing malicious scripts to be permanently injected into the site's content [1].

Exploitation requires user interaction from a privileged role (such as a site administrator) who must perform an action like clicking a malicious link or submitting a crafted form. Once executed, the injected script is stored within the WordPress backend and rendered for all subsequent visitors [1].

An attacker can leverage this stored XSS to inject arbitrary HTML or JavaScript payloads. This may include redirects, advertisement injections, or other malicious scripts that execute in the browser of every guest browsing the affected site [1].

As of the advisory, immediate action is recommended: update the plugin to a patched version if available. If updating is not possible, users should ask their hosting provider or web developer for assistance. The vulnerability is noted as being frequently used in mass-exploit campaigns [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.