Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Reilly Post-to-Post Links easy-post-to-post-links allows Stored XSS.This issue affects Post-to-Post Links: from n/a through <= 4.2.
Security readout for executives and security teams
Plain-English summary
This is a stored cross-site scripting issue in the WordPress Post-to-Post Links plugin up to version 4.2. A highly privileged user could save unsafe content that later runs in another user’s browser. The public sources do not show active exploitation or a named fixed version.
Executive priority
Treat as a moderate WordPress hygiene issue. Prioritize externally facing or multi-author sites, especially where many administrators or editors have access. Do not delay critical incidents for this unless local evidence shows abuse or the plugin is widely deployed across important sites.
Technical view
CVE-2025-23878 is CWE-79 improper input neutralization during web page generation in Scott Reilly Post-to-Post Links, package easy-post-to-post-links. It affects versions through 4.2. CVSS 3.1 is 5.9 with network access, low complexity, high privileges, required user interaction, changed scope, and low confidentiality, integrity, and availability impact.
Likely exposure
Exposure is limited to WordPress sites with Post-to-Post Links installed at version 4.2 or earlier. Risk depends on who has high-privilege WordPress access and whether stored plugin output is viewed by administrators, editors, or other authenticated users.
Exploitation context
The bundle does not cite CISA KEV listing or public active exploitation. The CVSS vector indicates exploitation requires a high-privilege attacker and user interaction, making opportunistic mass exploitation less likely than lower-privilege WordPress XSS, but stored execution can still affect trusted admin sessions.
Researcher notes
The evidence identifies stored XSS but does not provide vulnerable parameter detail, exploit status, or a fixed version in the supplied bundle. Validation should focus on asset inventory, version confirmation, role exposure, and vendor guidance rather than assumptions about exploit mechanics.
Mitigation direction
Inventory WordPress sites for the Post-to-Post Links plugin and version.
Check Patchstack and vendor guidance for any fixed release or removal advice.
Disable or remove the plugin where it is not business-critical.
Restrict high-privilege WordPress accounts to trusted users only.
Review stored content created by privileged users for suspicious entries.
Validation and detection
Confirm whether easy-post-to-post-links is installed on each WordPress site.
Record installed plugin versions and flag 4.2 or earlier.
Review WordPress user roles with permissions to create affected content.
Check security monitoring for suspicious admin-session script alerts.
Use safe authenticated scanning in staging, avoiding live exploit payloads.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.