Description
Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in plugin settings. Attackers can submit malicious payloads through textarea and input elements in the pwhois_settings.php configuration page to execute JavaScript in the admin context and escalate privileges.
Published: 2026-05-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a persistent cross‑site scripting flaw, identified as CWE‑79, that allows attackers who are authenticated as administrators to inject arbitrary JavaScript through unsanitized input fields on the plugin’s settings page. When the malicious code is stored and later rendered by the application, it executes in the context of an administrative user, effectively granting the attacker the same level of control over the site as a legitimate administrator, leading to privilege escalation and potential exposure of sensitive data or further compromise of the hosting environment.

Affected Systems

The flaw exists in Powie’s WHOIS Domain Check plugin, specifically version 0.9.31. The plugin is commonly used within WordPress sites to perform WHOIS lookups and display domain information. Only installations running this exact version are affected; newer or earlier releases are not impacted to the extent described.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity, but the fact that the exploit requires an authenticated administrator means the attacker must first gain legitimate access or have existing administrative credentials. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been observed yet. The attack path requires the victim to possess an admin role on the WordPress site, visit the vulnerable settings page, and submit a malicious payload, which is then stored and executed when the page is rendered. Once the script runs, the attacker can perform actions with the site's privileges.

Generated by OpenCVE AI on May 13, 2026 at 17:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Powie’s WHOIS Domain Check plugin to a version that contains the XSS fix.
  • If an upgrade is not immediately possible, deactivate and uninstall the plugin to eliminate the attack surface.
  • Limit administrative access to the plugin’s settings page to the minimum number of trusted users and ensure any user‑supplied data is properly sanitized or escaped before rendering.

Generated by OpenCVE AI on May 13, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 May 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 13 May 2026 15:15:00 +0000

Type Values Removed Values Added
Description Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in plugin settings. Attackers can submit malicious payloads through textarea and input elements in the pwhois_settings.php configuration page to execute JavaScript in the admin context and escalate privileges.
Title Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site Scripting
First Time appeared Powie
Powie pfile
Weaknesses CWE-79
CPEs cpe:2.3:a:powie:pfile:0.9.31:*:*:*:*:*:*:*
Vendors & Products Powie
Powie pfile
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-24T01:36:55.519Z

Reserved: 2026-05-13T14:16:30.648Z

Link: CVE-2020-37225

cve-icon Vulnrichment

Updated: 2026-05-13T18:32:33.516Z

cve-icon NVD

Status : Deferred

Published: 2026-05-13T16:16:34.127

Modified: 2026-05-13T17:07:21.030

Link: CVE-2020-37225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T17:15:26Z

Weaknesses