Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check wp-hosting-performance-check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through <= 2.18.8.
Published: 2025-01-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an instance of improper neutralization of input during web page generation, allowing an attacker to embed arbitrary script content in a page that is reflected back to the user. The vulnerability is classified as Cross‑Site Scripting (CWE‑79) and can be exploited when a user follows a crafted URL containing malicious code. Successful exploitation could lead to session hijacking, theft of user data granted to the vulnerable user, or the execution of additional malicious actions in the user’s browser context. The impact is limited to the affected user’s environment and does not provide direct system‑wide code execution.

Affected Systems

The WordPress plugin "wp Hosting Performance Check" developed by Scott Farrell is vulnerable. All versions from the initial release through 2.18.8 are affected. Upgrading to a later release eliminates the flaw.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity, and the EPSS value of less than 1% indicates a very low but non‑zero likelihood that this vulnerability will be exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS scenario where a maliciously crafted URL is sent to a user who visits the page, causing the injected script to execute in their browser. The exploitation requires no special privileges and relies solely on user interaction with the vulnerable page.

Generated by OpenCVE AI on May 2, 2026 at 06:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Hosting Performance Check plugin to the latest version (≥ 2.18.9) which removes the reflected XSS flaw.
  • If an upgrade cannot be performed immediately, disable or uninstall the plugin to eliminate the vulnerable endpoint until a patch becomes available.
  • Deploy a web application firewall rule that blocks or rejects URLs containing script tags or encoded script payloads targeting the WP Hosting Performance Check plugin’s query parameters.

Generated by OpenCVE AI on May 2, 2026 at 06:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2801 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through 2.18.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through 2.18.8. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check wp-hosting-performance-check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through <= 2.18.8.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 10 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through 2.18.8.
Title WordPress wp Hosting Performance Check Plugin <= 2.18.8 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:00.823Z

Reserved: 2025-01-07T10:22:48.985Z

Link: CVE-2025-22521

cve-icon Vulnrichment

Updated: 2025-01-10T20:18:04.888Z

cve-icon NVD

Status : Deferred

Published: 2025-01-09T16:16:27.743

Modified: 2026-06-17T08:47:57.877

Link: CVE-2025-22521

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:45:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')