Cross-site Scripting Vulnerability in Envo Extra by EnvoThemes
CVE-2025-66066

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 November 2025

What is CVE-2025-66066?

The Envo Extra plugin from EnvoThemes is susceptible to a Cross-site Scripting (XSS) vulnerability due to improper input sanitization during web page generation. This allows malicious users to inject harmful scripts into web pages that may then be stored and executed in the context of other users' browsers. The vulnerability affects versions of Envo Extra up to and including 1.9.11, highlighting the need for users to regularly update their plugins to safeguard against potential attacks.

Affected Version(s)

Envo Extra <= n/a

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abu Hurayra | Patchstack Bug Bounty Program
.
CVE-2025-66066 : Cross-site Scripting Vulnerability in Envo Extra by EnvoThemes