Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thaikolja Flexible Blogtitle flexible-blogtitle allows Reflected XSS.This issue affects Flexible Blogtitle: from n/a through <= 0.1.
Security readout for executives and security teams
Plain-English summary
WordPress sites using Flexible Blogtitle up to 0.1 may reflect unsafe input into generated pages. A tricked user could run attacker-controlled script in their browser. Business urgency depends on whether the plugin is installed; remove or disable it if present until vendor guidance confirms a safe path.
Executive priority
Handle as a focused high-priority WordPress plugin cleanup. The issue is serious for sites using this plugin, but current supplied evidence does not show active exploitation or impact beyond Flexible Blogtitle through 0.1.
Technical view
CVE-2025-23846 is a reflected XSS issue in thaikolja Flexible Blogtitle for WordPress, affecting versions through 0.1. The CVSS 3.1 score is 7.1 with network access, low complexity, no privileges, and required user interaction. The weakness is CWE-79: improper neutralization of input during web page generation.
Likely exposure
Exposure appears limited to WordPress installations with the flexible-blogtitle plugin installed at version 0.1 or earlier. The source bundle does not identify affected themes, core WordPress, hosted WordPress services, or other products.
Exploitation context
The source bundle marks KEV as false and provides no cited evidence of active exploitation. The attack requires user interaction, consistent with reflected XSS. Treat this as a link-click or phishing-driven browser risk, not evidence of automatic server compromise.
Researcher notes
Do not broaden scope beyond the named plugin and affected range. The public data supports reflected XSS with user interaction required. No patch version, exploit availability, or active exploitation evidence is included in the supplied sources.
Mitigation direction
Inventory WordPress sites for Flexible Blogtitle version 0.1 or earlier.
Disable or remove the plugin if it is not business-critical.
Check Patchstack and vendor guidance for an official fixed version or mitigation.
Prioritize action on administrator-facing or high-traffic WordPress sites.
Validation and detection
Confirm whether the flexible-blogtitle plugin is installed on each WordPress site.
Record installed plugin versions and compare them with the affected range through 0.1.
Review security tooling for reflected XSS alerts involving this plugin.
Verify any remediation by confirming the plugin is removed, disabled, or vendor-fixed.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.