Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in promact WP Azure offload wp-azure-offload allows Reflected XSS.This issue affects WP Azure offload: from n/a through <= 2.0.
Published: 2025-03-28
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Azure offload plugin for WordPress has an improper neutralization vulnerability that permits attacker‑supplied input to be reflected in the browser without adequate escaping. An attacker can inject malicious scripts into the generated web page, potentially hijacking user sessions or defacing content. This is a CWE‑79 Cross‑Site Scripting flaw, allowing execution of arbitrary script in the context of a victim’s browser, impacting confidentiality, integrity and availability of the user data and the web application.

Affected Systems

Affected are installations of the WP Azure offload plugin from the vendor promact, any WordPress site running plugin version 2.0 or earlier. The issue exists across the entire plugin version range that was released up to version 2.0, as explicitly enumerated in the advisory.

Risk and Exploitability

Because this is a reflected XSS flaw, the attack vector is likely remote and requires the victim to visit a crafted URL or click a malicious link; the vulnerability does not require authentication. The CVSS score of 7.1 indicates a high impact in the medium‑to‑high severity range. The EPSS score of less than 1% suggests a low probability that this flaw has been actively exploited in the wild at the time of analysis, and its absence from the CISA KEV catalog supports this inference. Nevertheless, a reflected XSS can compromise exposed user sessions or deface a site, so the risk remains significant for exposed websites.

Generated by OpenCVE AI on May 1, 2026 at 12:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Azure offload plugin to the latest available release (any version newer than 2.0).
  • If an upgrade is not immediately possible, ensure that any data reflected back by the plugin is properly sanitized or escaped, especially any URL query parameters that the plugin uses.
  • Disable or uninstall the WP Azure offload plugin if it is not required for the site’s functionality.

Generated by OpenCVE AI on May 1, 2026 at 12:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14970 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Azure offload allows Reflected XSS. This issue affects WP Azure offload: from n/a through 2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Azure offload allows Reflected XSS. This issue affects WP Azure offload: from n/a through 2.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in promact WP Azure offload wp-azure-offload allows Reflected XSS.This issue affects WP Azure offload: from n/a through <= 2.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 28 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Azure offload allows Reflected XSS. This issue affects WP Azure offload: from n/a through 2.0.
Title WordPress WP Azure offload plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:00.329Z

Reserved: 2025-01-03T13:16:57.347Z

Link: CVE-2025-22360

cve-icon Vulnrichment

Updated: 2025-03-28T15:58:09.633Z

cve-icon NVD

Status : Deferred

Published: 2025-03-28T15:15:46.653

Modified: 2026-06-17T08:46:45.993

Link: CVE-2025-22360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')