Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faaiq Pretty Url pretty-url allows Reflected XSS.This issue affects Pretty Url: from n/a through <= 1.5.4.
Published: 2025-01-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

faaiq Pretty Url plugin versions through 1.5.4 contain an improper neutralization of input during web page generation that allows an attacker to inject arbitrary HTML or JavaScript code into a page that is subsequently viewed by other users. The flaw, identified as CWE‑79, can lead to session hijacking, credential theft, defacement, or other attacks that compromise confidentiality, integrity and availability of the affected WordPress site. The description explicitly states that it is a reflected XSS issue, but the exact attack vector is not fully detailed; it is inferred that the vulnerability is triggered by forging a URL containing malicious input.

Affected Systems

Any WordPress site that has installed the faaiq Pretty Url plugin with a version number of 1.5.4 or earlier. No later versions are currently affected.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating medium‑to‑high severity, and an EPSS score of less than 1 % which suggests low but non‑zero probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Because the flaw is reflected, an attacker must supply a crafted request that includes malicious payloads, typically via a URL. Once the victim clicks the manipulated link, the injected code executes within the victim’s browser context, enabling the attacker to perform client‑side attacks such as cookie theft or further phishing.

Generated by OpenCVE AI on May 1, 2026 at 18:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Pretty Url plugin to a version newer than 1.5.4 once an official release is available.
  • If an upgrade cannot be performed immediately, disable or uninstall the Pretty Url plugin to eliminate the input vector.
  • As a temporary measure, apply a content‑security‑policy that blocks execution of inline scripts for the affected WordPress paths so that any reflected payloads are neutralized.

Generated by OpenCVE AI on May 1, 2026 at 18:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2842 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faaiq Pretty Url allows Reflected XSS. This issue affects Pretty Url: from n/a through 1.5.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faaiq Pretty Url allows Reflected XSS. This issue affects Pretty Url: from n/a through 1.5.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faaiq Pretty Url pretty-url allows Reflected XSS.This issue affects Pretty Url: from n/a through <= 1.5.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00035}

epss

{'score': 0.00045}


Fri, 31 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 08:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faaiq Pretty Url allows Reflected XSS. This issue affects Pretty Url: from n/a through 1.5.4.
Title WordPress Pretty Url Plugin <= 1.5.4 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:01.593Z

Reserved: 2025-01-07T10:23:24.212Z

Link: CVE-2025-22564

cve-icon Vulnrichment

Updated: 2025-01-31T19:28:51.224Z

cve-icon NVD

Status : Deferred

Published: 2025-01-31T09:15:07.627

Modified: 2026-06-17T08:48:18.537

Link: CVE-2025-22564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T18:15:22Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')