Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D verge3d allows Reflected XSS.This issue affects Verge3D: from n/a through <= 4.8.0.
Published: 2025-01-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of user input in the Verge3D publishing and e‑commerce plugin allows attackers to inject arbitrary JavaScript into web pages that are rendered to visitors. The vulnerability can lead to theft of session cookies, defacement, or execution of malicious code in the context of users navigating the site. The plugin’s input fields lack proper output encoding, making it possible for a crafted request to cause the browser to execute attacker‑supplied script code.

Affected Systems

Soft8Soft LLC"s Verge3D WordPress plugin, versions from the first release through 4.8.0, is affected. Any site running one of these legacy plugin versions is vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity for a Cross‑Site Scripting flaw. The EPSS score of less than 1 % suggests that exploit activity is currently rare, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is a reflected request that an attacker can drive from an external source, making the flaw exploitable without special privileges. Thus, while the impact is significant, the overall risk to an organization is moderated by the low exploitation probability set by the EPSS metric.

Generated by OpenCVE AI on May 1, 2026 at 20:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Verge3D 4.9.0 or later to eliminate the input validation flaw
  • Configure a web application firewall to block or sanitize JavaScript payloads in user‑provided parameters
  • If an upgrade is not immediately possible, remove or disable the Verge3D plugin from the WordPress installation

Generated by OpenCVE AI on May 1, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2933 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.8.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.8.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D verge3d allows Reflected XSS.This issue affects Verge3D: from n/a through <= 4.8.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 21 Jan 2025 14:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.8.0.
Title WordPress Verge3D Publishing and E-Commerce Plugin <= 4.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:05.548Z

Reserved: 2025-01-07T21:03:35.333Z

Link: CVE-2025-22709

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-01-21T14:15:10.823

Modified: 2026-06-17T08:49:27.000

Link: CVE-2025-22709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T20:15:24Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')