Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Post And Page Reactions post-and-page-reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through <= 1.0.5.
Published: 2025-01-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of user input during web page generation in the Post And Page Reactions plugin, which allows a reflected cross‑site scripting (XSS) injection. An attacker can embed malicious JavaScript that is echoed back in the HTTP response. If a victim clicks a crafted link or visits a malicious page, the script runs in the victim’s browser, potentially compromising session credentials, defacing content, or executing arbitrary actions as the user. This weakness is identified as CWE‑79.

Affected Systems

Affected installations are WordPress sites running the arete‑it Post And Page Reactions plugin version 1.0.5 or earlier. Any site that has not updated the plugin to a later version is vulnerable. The weakness resides entirely in the plugin code and impacts all user roles that can view the affected pages.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity with a low EPSS of less than 1% and the vulnerability is not listed in CISA KEV. Exploitation would typically involve an attacker crafting a URL with malicious payloads that are reflected in the browser, requiring the victim to click the link or visit a page containing the payload. The risk is moderate, with potential for client‑side compromise but no direct server compromise. Prompt remediation is recommended.

Generated by OpenCVE AI on May 2, 2026 at 06:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Post And Page Reactions 1.0.6 or later
  • If upgrade not possible, temporarily disable or delete the plugin from the WordPress site
  • Optionally deploy a web application firewall rule to block XSS payloads and monitor for suspicious activity

Generated by OpenCVE AI on May 2, 2026 at 06:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2844 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paramveer Singh for Arete IT Private Limited Post And Page Reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through 1.0.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paramveer Singh for Arete IT Private Limited Post And Page Reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through 1.0.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Post And Page Reactions post-and-page-reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through <= 1.0.5.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 13 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jan 2025 13:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paramveer Singh for Arete IT Private Limited Post And Page Reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through 1.0.5.
Title WordPress Post And Page Reactions Plugin <= 1.0.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:01.890Z

Reserved: 2025-01-07T10:23:33.283Z

Link: CVE-2025-22568

cve-icon Vulnrichment

Updated: 2025-01-13T14:43:48.919Z

cve-icon NVD

Status : Deferred

Published: 2025-01-13T14:15:11.610

Modified: 2026-06-17T08:48:20.540

Link: CVE-2025-22568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:45:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')