Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio Flexo Slider flexo-slider allows Reflected XSS.This issue affects Flexo Slider: from n/a through <= 1.0013.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected XSS flaw caused by improper neutralization of user‑controlled input during page rendering. An attacker can craft a request containing malicious scripts that are reflected back in the page served by the Flexo Slider plugin. If a user visits the crafted URL or interacts with the page, the injected code executes in the victim's browser, potentially compromising session cookies, redirecting to phishing sites or executing arbitrary actions under the victim's identity. This falls under CWE‑79 and represents a serious threat to confidentiality, integrity, and availability of authenticated users.

Affected Systems

The flaw affects all installations of the Flexo Slider plugin for WordPress up to and including version 1.0013. The plugin is distributed by flexostudio and is commonly used to embed sliders in WordPress sites. Any host running a vulnerable version is susceptible, regardless of the site’s broader WordPress configuration. The issue persists across all WordPress core versions that support the plugin; the plugin itself does not apply input sanitization to the parameters that generate slider output.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level, while the EPSS score of less than 1 % suggests the likelihood of exploitation in the wild is currently low. The vulnerability is not yet recorded in CISA’s Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw by sending a crafted URL or form input that the plugin processes and reflects back to the user's browser. Because the attack vector is web‑based and does not require privileged access, the risk is significant for any site exposed to the internet that has the plugin installed.

Generated by OpenCVE AI on May 1, 2026 at 15:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Flexo Slider to the latest release that removes the reflected XSS flaw; if no patch is available, uninstall the plugin.
  • Configure a web application firewall or apply a strict Content Security Policy (e.g., script-src 'self') to block execution of malicious scripts that might be injected by the plugin.
  • If the plugin must remain, manually sanitize any user‑supplied content that feeds slider parameters and limit custom code injections to privileged administrators.

Generated by OpenCVE AI on May 1, 2026 at 15:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5738 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Flexo Slider allows Reflected XSS. This issue affects Flexo Slider: from n/a through 1.0013.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Flexo Slider allows Reflected XSS. This issue affects Flexo Slider: from n/a through 1.0013. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio Flexo Slider flexo-slider allows Reflected XSS.This issue affects Flexo Slider: from n/a through <= 1.0013.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Flexo Slider allows Reflected XSS. This issue affects Flexo Slider: from n/a through 1.0013.
Title WordPress Flexo Slider plugin <= 1.0013 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:10.296Z

Reserved: 2025-01-16T11:25:13.028Z

Link: CVE-2025-23472

cve-icon Vulnrichment

Updated: 2025-03-03T15:56:45.010Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:36.497

Modified: 2026-06-17T08:54:38.590

Link: CVE-2025-23472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T15:15:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')