Junglewise Threat Intelligence

CVE-2025-22741: RiceTheme Felan Framework reflected XSS

CVE-2025-22741 · Severity: high · CVSS 7.1 · Published 2026-05-27

Executive brief

The Felan Framework, a WordPress plugin used for theme development, contains a security flaw that allows attackers to perform reflected cross-site scripting (XSS). By tricking a user into clicking a malicious link, an attacker can execute unauthorized scripts in the user's browser. This can lead to the theft of login sessions, unauthorized website changes, or the redirection of visitors to malicious websites.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the RiceTheme Felan Framework plugin for WordPress (versions up to and including 1.1.3). The vulnerability stems from the improper neutralization of user-supplied input during web page generation, allowing unauthenticated attackers to inject malicious scripts. Exploitation requires a victim to interact with a specially crafted link or form (User Interaction: Required). Successful exploitation can lead to session hijacking, sensitive data exposure, or unauthorized actions performed in the context of the victim's browser. As of the advisory date, no official patch has been released.

Affected products

  • RiceTheme Felan Framework n/a through 1.1.3

Timeline

  • 2025-08-27: other: Vulnerability reported by researcher 0xd4rk5id3
  • 2026-05-26: advisory: Patchstack advisory published
  • 2026-05-27: disclosed: CVE published to NVD dataset

References