Cyber Resilience

CVE-2025-68906

High

Published: 22 January 2026

Published
22 January 2026
Modified
15 April 2026
KEV Added
Patch
CVSS Score v3.1 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0006 20.3th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-68906 is a high-severity Cross-site Scripting (CWE-79) vulnerability. Its CVSS base score is 7.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 20.3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-15 (Information Output Filtering).

Deeper analysis

CVE-2025-68906 is an Improper Neutralization of Input During Web Page Generation vulnerability, classified as Reflected Cross-site Scripting (XSS) under CWE-79, in the jegtheme JNews - Video WordPress plugin. This issue affects the plugin from unknown initial versions through 11.0.2, allowing malicious input to be reflected without proper sanitization during web page generation.

The vulnerability carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L). Remote attackers require no privileges and can exploit it over the network with low complexity by tricking authenticated users into interacting with a malicious link or payload, such as via phishing. Exploitation results in reflected XSS, executing arbitrary JavaScript in the victim's browser context with changed scope, enabling limited impacts on confidentiality, integrity, and availability, such as session hijacking or data exfiltration.

The Patchstack advisory provides further details on this vulnerability in JNews - Video version 11.0.2, accessible at https://patchstack.com/database/Wordpress/Plugin/jnews-video/vulnerability/wordpress-jnews-video-plugin-11-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve.

EU & UK References

Vulnerability details

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - Video jnews-video allows Reflected XSS.This issue affects JNews - Video: from n/a through <= 11.0.2.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1566.002 Spearphishing Link Initial Access
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
T1059.007 JavaScript Execution
Adversaries may abuse various implementations of JavaScript for execution.
Why these techniques?

Reflected XSS in public-facing WordPress plugin directly enables exploitation via malicious links (phishing) to execute arbitrary JavaScript in browser context.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

CVEs Like This One

CVE-2026-28126Shared CWE-79
CVE-2025-23732Shared CWE-79
CVE-2025-22294Shared CWE-79
CVE-2025-68836Shared CWE-79
CVE-2025-23598Shared CWE-79
CVE-2025-68892Shared CWE-79
CVE-2026-27348Shared CWE-79
CVE-2026-31845Shared CWE-79
CVE-2025-22317Shared CWE-79
CVE-2025-27002Shared CWE-79

Affected Assets

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly requires validation and sanitization of all untrusted input before it is used in web page generation, blocking the reflected XSS payload at its source.

prevent

Requires filtering or encoding of information returned to users, preventing malicious scripts from being reflected and executed in the victim's browser.

preventdetect

Can enforce mechanisms that detect or block execution of unauthorized scripts delivered via reflected XSS vectors.

References