CVE-2025-63057

8.2

Roxnor · Wp Ultimate Review

A DOM-based cross-site scripting vulnerability exists in the Wp Ultimate Review plugin due to improper neutralization of user-supplied input.

Executive summary

The Roxnor Wp Ultimate Review plugin is vulnerable to DOM-based cross-site scripting, which could allow an authenticated attacker to execute malicious scripts in a user's browser session.

Vulnerability

This vulnerability is a DOM-based cross-site scripting (CWE-79) flaw. It requires an authenticated user with low-level privileges to interact with the vulnerable input mechanism, allowing for the injection and execution of arbitrary client-side scripts.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript within the context of a victim's browser session. This can lead to session hijacking, unauthorized actions performed on behalf of the user, or the theft of sensitive information. Given the CVSS score of 8.2, this flaw represents a high risk to organizational data integrity and user account security.

Remediation

Immediate Action: Since no specific patch version is currently identified, users should monitor the vendor's repository for updates and disable the Wp Ultimate Review plugin until a secure version is released.

Proactive Monitoring: Security teams should monitor web application access logs for suspicious patterns, such as unusual URL parameters or attempts to inject script tags into web forms.

Compensating Controls: Deploying a Web Application Firewall (WAF) with configured rules to detect and block common cross-site scripting payloads can provide a temporary layer of defense.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a significant risk to site users due to the potential for script injection. Organizations utilizing the Wp Ultimate Review plugin must prioritize the removal or deactivation of this component until the vendor provides a patched version to address the underlying input neutralization failure.

More Roxnor CVEs

Sources

Originally found and disclosed by zaim | Patchstack Bug Bounty Program, per the CVE Program record.