Cross-site Scripting Vulnerability in Enfold Theme by Kriesi
CVE-2025-66053

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
21 November 2025

What is CVE-2025-66053?

The Enfold theme by Kriesi is impacted by a Cross-site Scripting vulnerability that allows attackers to inject malicious scripts, facilitating Stored XSS attacks. This vulnerability affects versions of Enfold from an unspecified date up to and including version 7.1.2, potentially compromising the security of the web pages and users interacting with them. It underscores the need for timely updates and adequate web application security practices to mitigate such risks.

Affected Version(s)

Enfold <= n/a

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.
CVE-2025-66053 : Cross-site Scripting Vulnerability in Enfold Theme by Kriesi