Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlTi5 AlT Report alt-report allows Reflected XSS.This issue affects AlT Report: from n/a through <= 1.12.0.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw in the WordPress AlT Report plugin caused by improper neutralization of input during web page generation. A malicious request can cause user‑supplied data to be rendered unescaped, allowing the injection of arbitrary scripts that execute in the victim's browser. The official description does not detail specific attack outcomes, but typical reflected XSS can lead to session hijacking, defacement, or redirects; these effects are inferred from general XSS behavior.

Affected Systems

The flaw exists in the AlT Report plugin for WordPress, sold by AlTi5 under the module name AlT Report. It affects all releases from the earliest available version through version 1.12.0. Any WordPress site that has the plugin installed at or below that version is vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity for arbitrary script injection. The EPSS value of less than 1 % suggests that exploitation attempts are currently uncommon. The vulnerability is not listed in the CISA KEV catalog, so no widespread exploitation has been reported. The reflected nature of the flaw means it can be triggered just by a crafted URL and does not require authentication or elevated privileges, making the risk appreciable for publicly accessible sites.

Generated by OpenCVE AI on May 2, 2026 at 06:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AlT Report plugin to the latest release (greater than 1.12.0).
  • If an upgrade cannot be performed immediately, deploy a web application firewall or implement content‑security‑policy rules that mitigate reflected XSS by filtering inline scripts.
  • Validate and sanitize all user‑supplied input that the plugin processes, and ensure that HTTP response headers such as XSS protection and content‑type options are set correctly.

Generated by OpenCVE AI on May 2, 2026 at 06:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3179 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlTi5 AlT Report allows Reflected XSS.This issue affects AlT Report: from n/a through 1.12.0.
History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlTi5 AlT Report allows Reflected XSS.This issue affects AlT Report: from n/a through 1.12.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlTi5 AlT Report alt-report allows Reflected XSS.This issue affects AlT Report: from n/a through <= 1.12.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlTi5 AlT Report allows Reflected XSS.This issue affects AlT Report: from n/a through 1.12.0.
Title WordPress AlT Report plugin <= 1.12.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:53.707Z

Reserved: 2025-01-16T11:24:23.107Z

Link: CVE-2025-23432

cve-icon Vulnrichment

Updated: 2025-01-17T17:23:00.471Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:34.467

Modified: 2026-06-17T08:54:19.457

Link: CVE-2025-23432

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:30:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')