CVE-2025-54721: WordPress Resca theme <= 3.0.2 - Cross Site Scripting (XSS) vulnerability
Published Nov 6, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Resca resca allows Reflected XSS.This issue affects Resca: from n/a through <= 3.0.2.
Affected Software
2 affected components
thimpress Resca<=3.0.2
WordPress Resca theme<=3.0.2
Event History
Nov 6, 2025
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-54721?
CVE-2025-54721 has a high severity rating due to its potential for reflected cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-54721?
To fix CVE-2025-54721, update the ThimPress Resca theme to version 3.0.3 or later.
3
What types of systems are affected by CVE-2025-54721?
CVE-2025-54721 affects ThimPress Resca versions up to and including 3.0.2.
4
What is reflected cross-site scripting in the context of CVE-2025-54721?
Reflected cross-site scripting allows attackers to inject malicious scripts into web pages viewed by users, potentially stealing sensitive information.
5
Can CVE-2025-54721 affect user data?
Yes, CVE-2025-54721 has the potential to compromise user data by exploiting flaws in how input is handled during webpage generation.