Junglewise Threat Intelligence

CVE-2025-63021: codetipi Valenti Engine DOM-based cross-site scripting

CVE-2025-63021 · Severity: medium · CVSS 6.5 · Published 2025-12-31

Executive brief

Valenti Engine is a WordPress plugin used to build website content and layouts. The plugin contains a cross-site scripting (XSS) flaw that allows attackers to inject malicious scripts into pages, which could steal visitor data, hijack user accounts, or deface the site. Exploitation requires tricking a contributor or administrator into clicking a malicious link or visiting a crafted page.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in the codetipi Valenti Engine WordPress plugin (versions up to 1.0.3) caused by improper neutralization of user input during web page generation. The vulnerability allows attackers with contributor or higher privileges to inject malicious scripts that execute in the browser of other site visitors. Exploitation requires user interaction—a privileged user must click a malicious link or visit a crafted page. An attacker can steal session cookies, redirect users to phishing pages, or perform actions on behalf of compromised accounts. No official patch is currently available.

Affected products

  • codetipi Valenti Engine <= 1.0.3

Timeline

  • 2025-10-21: disclosed: Reported to Patchstack
  • 2025-12-31: advisory: Published by Patchstack and assigned CVE-2025-63021

References