Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bjoerne Navigation Du Lapin Blanc navigation-du-lapin-blanc allows DOM-Based XSS.This issue affects Navigation Du Lapin Blanc: from n/a through <= 1.1.1.
Published: 2025-01-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Navigation Du Lapin Blanc plugin for WordPress contains an improper neutralization of input during page generation that permits a DOM‑based cross‑site scripting (XSS) attack. An attacker can supply malicious JavaScript content that is subsequently rendered in the victim’s browser, potentially enabling the theft of session cookies, defacement of the user interface, or execution of arbitrary actions on behalf of the authenticated user. The weakness falls under CWE‑79, indicating that the data is not properly sanitized before inclusion in the generated document.

Affected Systems

WordPress users running the Navigation Du Lapin Blanc plugin from any earlier release through 1.1.1 are affected. The plugin is identified as bjoerne:Navigation Du Lapin Blanc. The vulnerability applies to all installations of these versions regardless of site theme or other plugins.

Risk and Exploitability

The CVSS score of 6.5 classifies this issue as moderate in severity. The very low EPSS score of < 1% suggests that, as of this assessment, exploitation in the wild is unlikely, and the weakness is not currently listed in the CISA Known Exploited Vulnerabilities catalog. On a technical level, the likely attack vector is the submission of crafted input—such as query parameters or form fields—through the plugin’s public interface, which is rendered into page content without adequate escaping. Because the vulnerability is DOM‑based, it requires that a user visit a page containing the crafted input, a condition that most attacker‑controlled hosts can satisfy with a single click or via embedded links.

Generated by OpenCVE AI on May 2, 2026 at 06:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Navigation Du Lapin Blanc plugin to the latest stable release that removes the XSS flaw.
  • If a patched version is not yet available, remove or disable the plugin to eliminate the vulnerable code path until a fix can be applied.
  • As a temporary measure, configure the plugin (or the site) to sanitize or remove any user‑supplied content that is rendered on the client side, ensuring that all dynamic data is properly escaped before insertion into the DOM.

Generated by OpenCVE AI on May 2, 2026 at 06:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2960 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Björn Weinbrenner Navigation Du Lapin Blanc allows DOM-Based XSS.This issue affects Navigation Du Lapin Blanc: from n/a through 1.1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Björn Weinbrenner Navigation Du Lapin Blanc allows DOM-Based XSS.This issue affects Navigation Du Lapin Blanc: from n/a through 1.1.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bjoerne Navigation Du Lapin Blanc navigation-du-lapin-blanc allows DOM-Based XSS.This issue affects Navigation Du Lapin Blanc: from n/a through <= 1.1.1.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 15 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Björn Weinbrenner Navigation Du Lapin Blanc allows DOM-Based XSS.This issue affects Navigation Du Lapin Blanc: from n/a through 1.1.1.
Title WordPress Navigation Du Lapin Blanc plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:06.672Z

Reserved: 2025-01-07T21:04:23.274Z

Link: CVE-2025-22745

cve-icon Vulnrichment

Updated: 2025-01-15T18:53:21.405Z

cve-icon NVD

Status : Deferred

Published: 2025-01-15T16:15:36.810

Modified: 2026-06-17T08:49:44.420

Link: CVE-2025-22745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:30:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')