CVE-2025-32305: WordPress FlatNews theme <= 5.8 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sneeit FlatNews allows Reflected XSS. This issue affects FlatNews: from n/a through 5.8.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sneeit WordPress FlatNews Theme flatnews allows Reflected XSS.This issue affects WordPress FlatNews Theme: from n/a through <= 5.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32305?
CVE-2025-32305 has been classified with a high severity due to its potential to allow attackers to execute arbitrary JavaScript in the context of the victim's browser.
How do I fix CVE-2025-32305?
To fix CVE-2025-32305, update Sneeit FlatNews or the WordPress FlatNews theme to versions above 5.8 where the vulnerability is addressed.
What types of systems are affected by CVE-2025-32305?
CVE-2025-32305 affects Sneeit FlatNews and the WordPress FlatNews theme versions up to and including 5.8.
What is reflected XSS in the context of CVE-2025-32305?
Reflected XSS in CVE-2025-32305 refers to the vulnerability that allows attackers to inject malicious scripts that are immediately reflected back to users without server-side validation.
Who is affected by the CVE-2025-32305 vulnerability?
Users of Sneeit FlatNews and the WordPress FlatNews theme could be vulnerable to attacks exploiting CVE-2025-32305 if they are running the specified affected versions.