Cyber Posture

CVE-2025-22353

High

Published: 07 January 2025

Published
07 January 2025
Modified
29 April 2026
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0018 38.9th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-22353 is a high-severity Cross-site Scripting (CWE-79) vulnerability. Its CVSS base score is 7.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 38.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-15 (Information Output Filtering).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly mitigates reflected XSS by filtering and encoding information outputs during web page generation to neutralize malicious scripts.

prevent

Prevents improper neutralization of input by validating user-supplied data at entry points, blocking malicious payloads before they reach web page generation.

prevent

Addresses the specific flaw in the WordPress plugin by requiring identification, reporting, and correction of vulnerabilities like this reflected XSS.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Reflected XSS in public-facing WordPress plugin directly enables remote exploitation of a web application vulnerability (T1190).

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bvads BVD Easy Gallery Manager bvd-easy-gallery-manager allows Reflected XSS.This issue affects BVD Easy Gallery Manager: from n/a through <= 1.0.6.

Deeper analysisAI

CVE-2025-22353 is an Improper Neutralization of Input During Web Page Generation vulnerability, classified as Reflected Cross-site Scripting (XSS) under CWE-79, in the bvads BVD Easy Gallery Manager WordPress plugin (bvd-easy-gallery-manager). This issue affects all versions of the plugin from n/a through 1.0.6 inclusive. The vulnerability was published on 2025-01-07.

With a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), the flaw can be exploited remotely over the network by unauthenticated attackers with low attack complexity. Exploitation requires user interaction, such as visiting a maliciously crafted URL or page. Successful attacks enable limited impacts on confidentiality, integrity, and availability within a changed scope, potentially allowing attackers to execute arbitrary scripts in the victim's browser context.

Patchstack's advisory at https://patchstack.com/database/Wordpress/Plugin/bvd-easy-gallery-manager/vulnerability/wordpress-bvd-easy-gallery-manager-plugin-1-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve documents the Reflected XSS vulnerability in BVD Easy Gallery Manager version 1.0.6.

Details

CWE(s)

CVEs Like This One

CVE-2026-23807Shared CWE-79
CVE-2025-27005Shared CWE-79
CVE-2025-68520Shared CWE-79
CVE-2026-0800Shared CWE-79
CVE-2025-26555Shared CWE-79
CVE-2025-46199Shared CWE-79
CVE-2024-56060Shared CWE-79
CVE-2025-23570Shared CWE-79
CVE-2024-56056Shared CWE-79
CVE-2025-70038Shared CWE-79

References