VYPR
Medium severity6.5NVD Advisory· Published Jan 8, 2026· Updated Apr 27, 2026

CVE-2025-68875

CVE-2025-68875

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming Password Reset flaming-password-reset allows Stored XSS.This issue affects Flaming Password Reset: from n/a through <= 1.0.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Flaming Password Reset plugin for WordPress ≤ 1.0.3 allows attackers to inject malicious scripts via unsanitized input.

Vulnerability

Overview

The Flaming Password Reset plugin for WordPress versions up to and including 1.0.3 contains a Stored Cross-Site Scripting (XSS) vulnerability [1]. The issue stems from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject arbitrary HTML and JavaScript code that is stored on the server and later executed in the browsers of visitors [1].

Exploitation

Prerequisites

Exploitation requires a privileged user to perform an action such as clicking a malicious link or submitting a crafted form [1]. Once triggered, the injected payload persists in the application and executes whenever other users view the affected page [1]. The attacker does not need high-volume traffic to succeed, as campaigns often target thousands of sites simultaneously [1].

Impact on

Affected Sites

Successful exploitation allows an attacker to inject malicious scripts including redirects, advertisements, or other HTML payloads [1]. These scripts execute when guests visit the compromised site, potentially leading to data theft, session hijacking, or further defacement [1].

Mitigation and

Remediation

The vendor has not yet released an official patch for this vulnerability [1]. As immediate action, administrators should update the plugin when a patched version becomes available or contact their hosting provider for assistance [1]. Patchstack has issued a mitigation rule to block attacks until an official fix can be safely applied [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.