Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chenyenming Ui Slider Filter By Price ui-slider-filter-by-price allows Reflected XSS.This issue affects Ui Slider Filter By Price: from n/a through <= 1.1.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ui Slider Filter By Price plugin fails to properly neutralize user supplied content before embedding it into a page, which allows an attacker to inject JavaScript that executes in the victim’s browser. This reflected cross‑site scripting flaw can be used to steal session cookies, obtain credentials, or perform other malicious actions in the context of the site. The weakness is a classic example of input validation failure and is catalogued as CWE‑79.

Affected Systems

All WordPress sites that have installed chenyenming’s Ui Slider Filter By Price plugin from any release through version 1.1 are potentially vulnerable. The flaw has not been fixed in any version up to and including 1.1, so any deployment of those releases is affected.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, but the EPSS value of less than 1% suggests a low chance of widespread exploitation at present. The vendor has not listed this issue in the CISA KEV database, reducing known attack prevalence. Typically, exploitation would involve an attacker crafting a malicious URL or input that exploits the plugin’s unfiltered output when the slider interface is rendered – a scenario that is inferred from the description of improper input neutralization.

Generated by OpenCVE AI on May 2, 2026 at 09:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to the latest version once an update addressing the XSS flaw is released.
  • If the plugin is not critical to site functionality, disable or delete it to eliminate the vulnerable code path.
  • Implement a content‑security‑policy that blocks inline script execution or enforce script validation on the server side to mitigate potential script injection while a patch is applied.

Generated by OpenCVE AI on May 2, 2026 at 09:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5722 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ui Slider Filter By Price allows Reflected XSS. This issue affects Ui Slider Filter By Price: from n/a through 1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ui Slider Filter By Price allows Reflected XSS. This issue affects Ui Slider Filter By Price: from n/a through 1.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chenyenming Ui Slider Filter By Price ui-slider-filter-by-price allows Reflected XSS.This issue affects Ui Slider Filter By Price: from n/a through <= 1.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ui Slider Filter By Price allows Reflected XSS. This issue affects Ui Slider Filter By Price: from n/a through 1.1.
Title WordPress Ui Slider Filter By Price plugin <= 1.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:13.075Z

Reserved: 2025-01-16T11:26:13.957Z

Link: CVE-2025-23555

cve-icon Vulnrichment

Updated: 2025-03-03T15:56:15.756Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:41.040

Modified: 2026-04-23T15:24:01.183

Link: CVE-2025-23555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:15:26Z

Weaknesses