Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.23.
Published: 2025-01-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw allowing attacker‑controlled input to be saved in the plugin’s data store and later rendered without proper neutralization. This can enable execution of arbitrary JavaScript within the context of any user who views the affected avatar content, potentially leading to data theft, session hijacking, or defacement.

Affected Systems

The flaw affects the Author Avatars List/Block WordPress plugin developed by Paul Bearne in all releases up to and including version 2.1.23. Any WordPress installation that has this plugin installed and uses the avatar display functionality is potentially impacted.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating moderate severity, while the EPSS score is less than 1%, implying a very low likelihood of exploitation at the time of analysis. The flaw is not listed in CISA’s KEV catalog. Likely attack vectors involve the plugin’s input fields that store avatar data, which are rendered without escaping. An attacker would need to inject malicious script via those fields and then entice users to view the affected content. No known public exploits have been reported, so the risk remains primarily theoretical until mitigated.

Generated by OpenCVE AI on May 2, 2026 at 06:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Author Avatars List/Block plugin to a version newer than 2.1.23 that resolves the XSS issue.
  • If an update is not immediately available, disable the plugin or remove the avatar display feature from the site to prevent exploitation.
  • Apply server‑side sanitation to any avatar URLs or data stored by the plugin until a patch is released.

Generated by OpenCVE AI on May 2, 2026 at 06:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3008 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.23.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.23. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.23.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 10 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.23.
Title WordPress Author Avatars List/Block plugin <= 2.1.23 - Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:07.569Z

Reserved: 2025-01-07T21:05:34.184Z

Link: CVE-2025-22804

cve-icon Vulnrichment

Updated: 2025-01-10T20:18:36.124Z

cve-icon NVD

Status : Deferred

Published: 2025-01-09T16:16:29.787

Modified: 2026-06-17T08:50:12.497

Link: CVE-2025-22804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:45:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')