MEDIUM
jcaruso001
CVE published 2026-01-08
CVE-2025-68875
A Cross-site Scripting (XSS) vulnerability exists in the Flaming Password Reset plugin for WordPress, affecting versions up to and including 1.0.3. This issue allows for Stored XSS, potentially enabling attackers to inject malicious scripts into web pages viewed by other users. The vulnerability has a CVSS score of 6.5 and is considered MEDIUM severity. Defenders should verify exposure, prioritize updates [truncated]