Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhizome Networks CG Button content-glass-button allows Reflected XSS.This issue affects CG Button: from n/a through <= 1.0.5.6.
Published: 2025-03-26
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation in the CG Button WordPress plugin, classified as a reflected XSS flaw (CWE‑79). When a victim opens a crafted URL containing malicious script, the script is echoed back in the browser without sanitization. An attacker can exploit this to execute arbitrary JavaScript in the context of the site, potentially stealing session cookies, defacing content, or executing further phishing operations. The impact is limited to the victim user whose browser renders the injected code, but because the site may be used by many users, the effect can be widespread.

Affected Systems

The affected product is Rhizome Networks’ CG Button (content‑glass‑button) WordPress plugin, versions from the initial release up to and including 1.0.5.6. No later versions were listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity for client‑side attacks. The EPSS score of less than 1% suggests a low overall likelihood of exploitation at present, and the vulnerability is not currently listed in the CISA KEV catalog. The most probable attack vector is a user clicking a malicious link or visiting a crafted URL; no user authentication or elevated privileges are required. Consequently, the risk grows from high impact but low exploit probability towards a higher priority when a site’s public audience is large or the plugin is used to display user‑generated content.

Generated by OpenCVE AI on May 1, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the CG Button plugin to a version newer than 1.0.5.6.
  • If an upgrade is not feasible, uninstall or disable the CG Button plugin entirely.
  • Implement a Web Application Firewall rule to block reflected XSS attempts and sanitize user inputs on the site.

Generated by OpenCVE AI on May 1, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8192 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhizome Networks CG Button allows Reflected XSS. This issue affects CG Button: from n/a through 1.0.5.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhizome Networks CG Button allows Reflected XSS. This issue affects CG Button: from n/a through 1.0.5.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhizome Networks CG Button content-glass-button allows Reflected XSS.This issue affects CG Button: from n/a through <= 1.0.5.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 26 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhizome Networks CG Button allows Reflected XSS. This issue affects CG Button: from n/a through 1.0.5.6.
Title WordPress CG Button plugin <= 1.0.5.6 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:15.931Z

Reserved: 2025-01-16T11:27:31.285Z

Link: CVE-2025-23632

cve-icon Vulnrichment

Updated: 2025-03-26T15:44:17.044Z

cve-icon NVD

Status : Deferred

Published: 2025-03-26T15:15:58.530

Modified: 2026-06-17T08:55:57.153

Link: CVE-2025-23632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T13:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')