Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Private Messages for UserPro userpro-messaging allows Reflected XSS.This issue affects Private Messages for UserPro: from n/a through <= 4.10.0.
Published: 2025-01-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin contains an improper neutralization of input during page generation, resulting in a reflected XSS flaw (CWE‑79). A malicious user can embed arbitrary script into a URL that the plugin echoes back to the browser without sanitization. When a victim opens the URL the script is executed in the victim’s session, potentially allowing the attacker to read cookies, deface the page, or perform other in‑page actions. The impact is limited to the user interacting with the affected URL and does not persist data beyond that request.

Affected Systems

All installations of the DeluxeThemes Private Messages for UserPro WordPress plugin with version 4.10.0 or earlier are affected. This includes any WordPress site that has deployed the plugin in its messaging functionality.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑impact vulnerability. The EPSS score of less than 1 % signals a low likelihood of current exploitation, and the flaw is not listed in CISA’s KEV catalog, suggesting no known widespread attacks. It is inferred that the attack requires an attacker to craft a malicious URL and that a target user must subsequently visit that URL for the payload to execute, implying remote exploitation that relies on user interaction.

Generated by OpenCVE AI on May 2, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the DeluxeThemes Private Messages for UserPro plugin to the latest version (≥ 4.10.1) where the XSS flaw is fixed.
  • If an immediate upgrade is not possible, temporarily disable or uninstall the plugin to prevent exploitation.
  • Implement WordPress security measures such as a Web Application Firewall or input sanitization to block malicious script payloads in URLs.

Generated by OpenCVE AI on May 2, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2722 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Private Messages for UserPro allows Reflected XSS. This issue affects Private Messages for UserPro: from n/a through 4.10.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Private Messages for UserPro allows Reflected XSS. This issue affects Private Messages for UserPro: from n/a through 4.10.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Private Messages for UserPro userpro-messaging allows Reflected XSS.This issue affects Private Messages for UserPro: from n/a through <= 4.10.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 21 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Private Messages for UserPro allows Reflected XSS. This issue affects Private Messages for UserPro: from n/a through 4.10.0.
Title WordPress Private Messages for UserPro plugin <= 4.10.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:10:59.384Z

Reserved: 2025-01-03T13:16:25.401Z

Link: CVE-2025-22322

cve-icon Vulnrichment

Updated: 2025-01-21T14:33:33.107Z

cve-icon NVD

Status : Deferred

Published: 2025-01-21T14:15:10.280

Modified: 2026-06-17T08:46:27.837

Link: CVE-2025-22322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T11:30:41Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')