Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew BizLibrary bizlibrary allows Reflected XSS.This issue affects BizLibrary: from n/a through <= 1.1.
Published: 2025-01-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The BizLibrary WordPress plugin contains an improper neutralization of input during page generation that allows attackers to inject malicious script when a victim visits a crafted URL. This is a reflected XSS vulnerability (CWE‑79). The injected script can steal cookies, deface content, or redirect users, compromising any user who accesses the affected page.

Affected Systems

All installations of the Matthew BizLibrary plugin version 1.1 or earlier on WordPress sites. These plugins are commonly used for event or booking features and are deployed on sites that have not yet applied the latest version.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity level. The EPSS score is below 1 %, suggesting that exploitation attempts are expected to be rare and the vulnerability is not currently catalogued in CISA’s KEV. Until a fix is applied, an attacker can embed a malicious script into URLs that are reflected by the plugin, enabling the script to execute in the victim’s browser.

Generated by OpenCVE AI on May 1, 2026 at 19:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the BizLibrary plugin to version 1.2 or later, or uninstall the plugin if it is no longer required.
  • If an upgrade is not immediately possible, block or sanitize the parameters that are reflected by the plugin so that user input is escaped before output.
  • Add a Content‑Security‑Policy header that restricts inline scripts and disallows unsafe eval to mitigate any residual XSS impact.

Generated by OpenCVE AI on May 1, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3261 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew Garvin BizLibrary allows Reflected XSS. This issue affects BizLibrary: from n/a through 1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew Garvin BizLibrary allows Reflected XSS. This issue affects BizLibrary: from n/a through 1.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew BizLibrary bizlibrary allows Reflected XSS.This issue affects BizLibrary: from n/a through <= 1.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 21 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew Garvin BizLibrary allows Reflected XSS. This issue affects BizLibrary: from n/a through 1.1.
Title WordPress BizLibrary plugin <= 1.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:13.614Z

Reserved: 2025-01-16T11:26:29.091Z

Link: CVE-2025-23580

cve-icon Vulnrichment

Updated: 2025-01-21T18:35:59.844Z

cve-icon NVD

Status : Deferred

Published: 2025-01-21T18:15:17.133

Modified: 2026-06-17T08:55:32.163

Link: CVE-2025-23580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T20:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')