Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Mimoun-Prat WP PT-Viewer wp-ptviewer allows Reflected XSS.This issue affects WP PT-Viewer: from n/a through <= 2.0.2.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Reflected Cross‑Site Scripting flaw in the WordPress WP PT‑Viewer plugin caused by improper input neutralization in generated web pages, allowing an attacker to inject and execute arbitrary JavaScript while a victim views a crafted page. This could enable session hijacking, defacement, or malicious payload delivery within the victim’s browser context.

Affected Systems

Vendors: Vincent Mimoun‑Prat – product WP PT‑Viewer. All installations of the plugin with a version of 2.0.2 or earlier are vulnerable. The flaw is present in every release up to 2.0.2.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact, but the EPSS score of less than 1% reflects a low current exploitation probability, and the issue is not listed in the CISA KEV catalog. The flaw is typically exploited remotely by sending a malicious link that contains tampered parameters to a user who then visits the page, causing client‑side script execution. Because it is a reflected XSS, an attacker only needs the victim to load a crafted page; no prior authentication is required, making it relatively easy to launch but limited to the victim’s browser session.

Generated by OpenCVE AI on May 1, 2026 at 21:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP PT‑Viewer to version 2.0.3 or later, if a vendor patch is available.
  • If an update is not yet available, immediately disable the WP PT‑Viewer plugin or restrict its use to trusted users only.
  • Implement input sanitization or output encoding for all plugin parameters, or deploy a web application firewall rule to block JavaScript payloads injected by the plugin.

Generated by OpenCVE AI on May 1, 2026 at 21:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3183 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MarvinLabs WP PT-Viewer allows Reflected XSS.This issue affects WP PT-Viewer: from n/a through 2.0.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MarvinLabs WP PT-Viewer allows Reflected XSS.This issue affects WP PT-Viewer: from n/a through 2.0.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Mimoun-Prat WP PT-Viewer wp-ptviewer allows Reflected XSS.This issue affects WP PT-Viewer: from n/a through <= 2.0.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 16 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MarvinLabs WP PT-Viewer allows Reflected XSS.This issue affects WP PT-Viewer: from n/a through 2.0.2.
Title WordPress WP PT-Viewer plugin <= 2.0.2 - Reflected XSS vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T22:56:50.289Z

Reserved: 2025-01-16T11:24:23.108Z

Link: CVE-2025-23438

cve-icon Vulnrichment

Updated: 2025-01-16T20:24:05.945Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:35.067

Modified: 2026-06-17T08:54:22.317

Link: CVE-2025-23438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:30:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')