Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra bp-profile-shortcodes-extra allows Stored XSS.This issue affects BP Profile Shortcodes Extra: from n/a through <= 2.6.0.
Published: 2025-01-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The BP Profile Shortcodes Extra plugin contains an improper neutralization of input during web page generation, allowing attackers to store malicious scripts in profile data. If an attacker injects code into a field that the plugin renders without sanitization, the script will execute in any victim’s browser who views that profile, potentially leading to cookie theft, session hijack, defacement, or unauthorized redirects. This is a classic Stored XSS flaw, identified by CWE‑79.

Affected Systems

The vulnerability affects the Venutius BP Profile Shortcodes Extra WordPress plugin versions up to and including 2.6.0. Users running any of these releases are exposed.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows that the probability of exploitation is low, and the vulnerability is not yet listed in CISA's KEV catalog. The most likely attack vector is remote: an attacker who can submit content through the plugin’s input fields can embed malicious code that persists in the site and is served to all visitors of the affected profile pages. No active exploitation reports are evident, but the impact is substantial for users who rely on the plugin for public or private profiles.

Generated by OpenCVE AI on May 1, 2026 at 22:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade BP Profile Shortcodes Extra to the latest available version that removes the XSS flaw.
  • If upgrading is not currently possible, consider deactivating or uninstalling the plugin entirely, or disabling the shortcodes that allow user‑generated content.
  • Implement site‑wide content‑security‑policy headers and configure WordPress to strip disallowed tags from profile fields, mitigating the risk of stored XSS if the plugin is required.

Generated by OpenCVE AI on May 1, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3020 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra allows Stored XSS.This issue affects BP Profile Shortcodes Extra: from n/a through 2.6.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra allows Stored XSS.This issue affects BP Profile Shortcodes Extra: from n/a through 2.6.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra bp-profile-shortcodes-extra allows Stored XSS.This issue affects BP Profile Shortcodes Extra: from n/a through <= 2.6.0.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 10 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra allows Stored XSS.This issue affects BP Profile Shortcodes Extra: from n/a through 2.6.0.
Title WordPress BP Profile Shortcodes Extra plugin <= 2.6.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Venutius Bp Profile Shortcodes Extra
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:08.109Z

Reserved: 2025-01-07T21:05:44.629Z

Link: CVE-2025-22817

cve-icon Vulnrichment

Updated: 2025-01-10T20:19:10.694Z

cve-icon NVD

Status : Deferred

Published: 2025-01-09T16:16:31.693

Modified: 2026-04-23T15:23:40.723

Link: CVE-2025-22817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T22:15:27Z

Weaknesses