CVE-2025-53423: WordPress Triss theme <= 2.6 - Cross Site Scripting (XSS) vulnerability
Published Oct 22, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Triss triss allows Reflected XSS.This issue affects Triss: from n/a through <= 2.6.
Affected Software
2 affected components
designthemes Triss<=2.6
WordPress Triss<=2.6
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-53423?
CVE-2025-53423 is classified as a moderate severity Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-53423?
To fix CVE-2025-53423, update the Triss theme to version 2.7 or later, where the vulnerability has been addressed.
3
Who is affected by CVE-2025-53423?
CVE-2025-53423 affects users of the designthemes Triss theme version 2.6 or earlier.
4
What type of vulnerability is CVE-2025-53423?
CVE-2025-53423 is a reflected Cross-site Scripting (XSS) vulnerability.
5
How can CVE-2025-53423 be exploited?
CVE-2025-53423 can be exploited by injecting malicious scripts into web pages that are rendered in the browser of users visiting vulnerable pages.