DOM-Based XSS Exposure in SKT Skill Bar by Sonal Sinha
CVE-2025-66090

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 November 2025

What is CVE-2025-66090?

A vulnerability exists in the SKT Skill Bar plugin developed by Sonal Sinha, characterized by an improper neutralization of input during web page generation. This flaw allows for DOM-based Cross-site Scripting (XSS), enabling attackers to inject malicious scripts into webpages viewed by users. As a result, sensitive user data could be compromised, and site integrity might be at risk. Versions up to and including 2.5 are impacted, necessitating prompt action to mitigate potential exploitation.

Affected Version(s)

SKT Skill Bar <= n/a

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ | Patchstack Bug Bounty Program
.
CVE-2025-66090 : DOM-Based XSS Exposure in SKT Skill Bar by Sonal Sinha