Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M Bilal M Urdu Formatter – Shamil urdu-formatter-shamil allows Stored XSS.This issue affects Urdu Formatter – Shamil: from n/a through <= 0.1.
Published: 2025-01-07
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, specifically a Stored Cross‑Site Scripting (XSS) flaw. Attackers can inject malicious scripts that are later rendered by browsers when the affected plugin displays the data. The compromised scripts run with the privileges of the site, potentially stealing session cookies, defacing content, or redirecting users. The weakness corresponds to CWE‑79.

Affected Systems

The issue affects the Urdu Formatter – Shamil plugin developed by M Bilal M for WordPress. Any installation of the plugin at version 0.1 or earlier is impacted. No specific WordPress core version is listed; the plugin is compatible with WordPress installations that include the Urdu Formatter – Shamil.

Risk and Exploitability

The CVSS base score of 6.5 classifies the flaw as moderate but still notable. The EPSS score is less than 1 %, indicating that while the vendor is aware, the threat is considered low probability at present. The flaw is not in the CISA KEV catalog. Attacking typically requires exploiting a site that accepts and stores user‑supplied data via the plugin. An attacker would need to register or supply figure to be persisted, then later trick a victim to view the stored content. If the site has an unrestricted context for script execution, the injected code can run in the victim’s browser, giving the attacker whatever privileges the victim holds on the site.

Generated by OpenCVE AI on April 29, 2026 at 16:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patched version of Urdu Formatter – Shamil that resolves the XSS flaw
  • If a patched version is not available, uninstall or disable the plugin to remove the attack surface
  • If the plugin is required but cannot be upgraded, sanitize all user inputs before storage and restrict the data entry points to trusted users only

Generated by OpenCVE AI on April 29, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2809 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M Bilal M Urdu Formatter – Shamil allows Stored XSS.This issue affects Urdu Formatter – Shamil: from n/a through 0.1.
History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M Bilal M Urdu Formatter – Shamil allows Stored XSS.This issue affects Urdu Formatter – Shamil: from n/a through 0.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M Bilal M Urdu Formatter – Shamil urdu-formatter-shamil allows Stored XSS.This issue affects Urdu Formatter – Shamil: from n/a through <= 0.1.
References

Fri, 20 Jun 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Mbilalm
Mbilalm urdu Formatter
CPEs cpe:2.3:a:mbilalm:urdu_formatter:*:*:*:*:*:wordpress:*:*
Vendors & Products Mbilalm
Mbilalm urdu Formatter

Tue, 07 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M Bilal M Urdu Formatter – Shamil allows Stored XSS.This issue affects Urdu Formatter – Shamil: from n/a through 0.1.
Title WordPress Urdu Formatter – Shamil plugin <= 0.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Mbilalm Urdu Formatter
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:43:19.019Z

Reserved: 2025-01-07T10:22:58.147Z

Link: CVE-2025-22531

cve-icon Vulnrichment

Updated: 2025-01-07T16:06:28.080Z

cve-icon NVD

Status : Modified

Published: 2025-01-07T16:15:48.520

Modified: 2026-04-01T16:22:14.070

Link: CVE-2025-22531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T17:00:13Z

Weaknesses