Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in goldsounds VR Views vr-views allows Stored XSS.This issue affects VR Views: from n/a through <= 1.5.1.
Published: 2025-01-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of Input During Web Page Generation causes a stored cross‑site scripting vulnerability in the VR Views plugin. The flaw allows an attacker to embed malicious scripts that are stored and later rendered on pages, enabling arbitrary JavaScript execution in visitors' browsers.

Affected Systems

The vulnerability affects the WordPress VR Views plugin version numbering through 1.5.1, released by the vendor goldsounds. All plugin releases from the initial version up to and including 1.5.1 are susceptible.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate exploitation difficulty with client‑side impact. The EPSS score of less than 1% suggests low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need to inject malicious content through an administrative or content‑creation interface, which is then stored in the database and later served to users. Once executed, the embedded scripts run with the privileges of the visiting browser, potentially compromising user accounts or distributing malware.

Generated by OpenCVE AI on May 2, 2026 at 06:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the VR Views plugin to the latest version (≥1.5.2) where the stored XSS flaw is fixed.
  • After upgrading, purge any cached or legacy content that might still contain the malicious payloads introduced while the vulnerable version was in use.
  • Implement stricter input sanitization and output escaping for all plugin‑generated content, for example by applying WordPress’s wp_kses filters or a dedicated security plugin that blocks untrusted script tags.

Generated by OpenCVE AI on May 2, 2026 at 06:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3023 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Walmsley VR Views allows Stored XSS.This issue affects VR Views: from n/a through 1.5.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Walmsley VR Views allows Stored XSS.This issue affects VR Views: from n/a through 1.5.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in goldsounds VR Views vr-views allows Stored XSS.This issue affects VR Views: from n/a through <= 1.5.1.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 10 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Walmsley VR Views allows Stored XSS.This issue affects VR Views: from n/a through 1.5.1.
Title WordPress VR Views plugin <= 1.5.1 - Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:08.093Z

Reserved: 2025-01-07T21:05:54.009Z

Link: CVE-2025-22820

cve-icon Vulnrichment

Updated: 2025-01-10T20:19:19.759Z

cve-icon NVD

Status : Deferred

Published: 2025-01-09T16:16:32.173

Modified: 2026-06-17T08:50:20.117

Link: CVE-2025-22820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:45:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')