Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wjharil AdsMiddle adsmiddle allows Reflected XSS.This issue affects AdsMiddle: from n/a through <= 1.0.
Published: 2025-02-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AdsMiddle plugin for WordPress contains a reflected cross‑site scripting flaw that allows an attacker to inject arbitrary JavaScript into pages returned to the victim. This flaw is caused by improper neutralization of user‑controlled input when the plugin generates content. Because the payload is reflected, an attacker can trigger the vulnerability simply by crafting a malicious URL and encouraging a user to visit it. Successful exploitation can execute arbitrary code within the victim’s browser, enabling session hijacking, credential theft, or defacement of the authenticated session.

Affected Systems

All installations of the AdsMiddle plugin version 1.0 and earlier, developed by wjharil, are impacted. The vulnerability exists in every build up to 1.0, so any WordPress site running that code is vulnerable unless the plugin has been upgraded beyond that version.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is currently rare. The issue is not listed in the CISA KEV catalog, implying no known widespread attacks. The attack vector is likely phishing or malicious link delivery, requiring the victim to click a crafted URL. While the flaw requires user interaction, a well‑crafted social engineering campaign could compromise many users’ sessions and privacy.

Generated by OpenCVE AI on May 1, 2026 at 16:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AdsMiddle plugin to the latest available version (≥1.1) which eliminates the reflected XSS flaw.
  • If an upgrade is not immediately possible, sanitize all user‑supplied data before rendering it in the browser, ensuring that any special characters are properly escaped.
  • Disable any untrusted input fields within the plugin’s configuration or remove the plugin entirely if it is no longer needed.

Generated by OpenCVE AI on May 1, 2026 at 16:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3312 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wjharil AdsMiddle allows Reflected XSS. This issue affects AdsMiddle: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wjharil AdsMiddle allows Reflected XSS. This issue affects AdsMiddle: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wjharil AdsMiddle adsmiddle allows Reflected XSS.This issue affects AdsMiddle: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00032}

epss

{'score': 0.00035}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00072}

epss

{'score': 0.00032}


Fri, 14 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Feb 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wjharil AdsMiddle allows Reflected XSS. This issue affects AdsMiddle: from n/a through 1.0.
Title WordPress AdsMiddle plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:15.228Z

Reserved: 2025-01-16T11:27:38.285Z

Link: CVE-2025-23648

cve-icon Vulnrichment

Updated: 2025-02-14T15:35:55.948Z

cve-icon NVD

Status : Deferred

Published: 2025-02-14T13:15:44.930

Modified: 2026-06-17T08:56:04.920

Link: CVE-2025-23648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T16:45:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')