Description
The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nxt-year' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2025-12-02
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Plugin
AI Analysis

Impact

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to stored cross‑site scripting through its 'nxt-year' shortcode in all versions up to 4.4.1. The flaw arises because the plugin does not properly sanitize or escape user‑supplied input that is stored and rendered later. An authenticated user with Contributor‑level access can inject arbitrary JavaScript, which then executes in the browsers of anyone who views the affected page, potentially leading to session hijacking, credential theft or site defacement. This weakness corresponds to CWE‑79.

Affected Systems

This vulnerability affects the Nexter Extension – Security, Performance, Code Snippets & Site Toolkit plugin developed by posimyththemes for WordPress. All installations using the plugin in version 4.4.1 or earlier are impacted; versions newer than 4.4.1 are not known to contain the flaw.

Risk and Exploitability

The CVSS score of 6.4 marks this vulnerability as moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog, so no widespread exploits are reported. Exploitation requires authenticated access with at least Contributor privileges, suggesting the threat is confined to users who can edit content via the plugin. Once a malicious script is stored, it will run in any browser that renders the affected page, providing broad impact on all visitors. The likely attack vector is the plugin’s shortcode editor where an authenticated user can input the malicious code.

Generated by OpenCVE AI on April 22, 2026 at 00:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Nexter Extension plugin to version 4.4.2 or newer.
  • If an update cannot be applied, disable the plugin or delete the 'nxt-year' shortcode from all pages and posts.
  • Modify user roles so that Contributor‑level accounts cannot add or edit shortcodes in the plugin.

Generated by OpenCVE AI on April 22, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Dec 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 02 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 14:00:00 +0000

Type Values Removed Values Added
Description The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nxt-year' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Nexter Extension <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:03:36.843Z

Reserved: 2025-11-26T00:15:39.317Z

Link: CVE-2025-13731

cve-icon Vulnrichment

Updated: 2025-12-02T14:25:48.820Z

cve-icon NVD

Status : Deferred

Published: 2025-12-02T14:16:22.920

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-13731

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T00:30:04Z

Weaknesses