Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jas Saran G Web Pro Store Locator gwebpro-store-locator allows Reflected XSS.This issue affects G Web Pro Store Locator: from n/a through <= 2.0.1.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The G Web Pro Store Locator plugin from Jas Saran contains an improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts that are reflected back to users who visit a crafted URL. The vulnerability is characterized as Cross‑Site Scripting (CWE‑79) and can lead to session hijacking, credential theft, or the execution of arbitrary code within the victim’s browser. The CVSS score of 7.1 indicates a high likelihood of exploitation, although the EPSS score of less than 1% suggests it is not a common target today. The flaw resides in the way the plugin processes parameters that are displayed on store locator pages.

Affected Systems

Jas Saran G Web Pro Store Locator plugin, versions up to and including 2.0.1. Users running any installation of this plugin prior to version 2.0.2 are affected and should upgrade as soon as possible.

Risk and Exploitability

Based on the described behavior, an attacker can trigger the reflected XSS by embedding malicious script tags in query parameters or other data points that the plugin echoes without proper encoding. The low EPSS score indicates that exploitation is not widespread, and because the plugin likely runs on public websites, the impact could be community‑wide if a malicious link is distributed. The vulnerability does not appear in CISA’s KEV catalog, reducing the likelihood of a publicly‑known active exploit but still warrants immediate attention. The CVSS score underscores a high severity, requiring prompt mitigations.

Generated by OpenCVE AI on May 1, 2026 at 14:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the G Web Pro Store Locator plugin to version 2.0.2 or later, which contains input sanitization fixes.
  • If an upgrade cannot be performed immediately, temporarily deactivate the plugin or restrict its front‑end access to authenticated users only to prevent unauthenticated browsers from rendering vulnerable pages.
  • Apply a web‑application firewall rule to block suspicious query strings that contain script tags or encode characters typically used in XSS attacks.
  • Continuously monitor site logs and user feedback for signs of XSS exploitation and validate that no reflected scripts appear in rendered pages.

Generated by OpenCVE AI on May 1, 2026 at 14:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5724 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound G Web Pro Store Locator allows Reflected XSS. This issue affects G Web Pro Store Locator: from n/a through 2.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound G Web Pro Store Locator allows Reflected XSS. This issue affects G Web Pro Store Locator: from n/a through 2.0.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jas Saran G Web Pro Store Locator gwebpro-store-locator allows Reflected XSS.This issue affects G Web Pro Store Locator: from n/a through <= 2.0.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 05 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound G Web Pro Store Locator allows Reflected XSS. This issue affects G Web Pro Store Locator: from n/a through 2.0.1.
Title WordPress G Web Pro Store Locator plugin <= 2.0.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:11.916Z

Reserved: 2025-01-16T11:25:42.451Z

Link: CVE-2025-23519

cve-icon Vulnrichment

Updated: 2025-03-05T17:05:25.158Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:39.487

Modified: 2026-04-23T15:23:56.267

Link: CVE-2025-23519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T15:00:13Z

Weaknesses