Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sav WP OpenSearch wp-opensearch allows Stored XSS.This issue affects WP OpenSearch: from n/a through <= 1.0.
Published: 2025-01-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin allows an attacker to store malicious scripts that are executed whenever a site visitor loads a page that displays the affected content. This stored XSS flaw gives the attacker the ability to run arbitrary JavaScript in the context of the site, potentially stealing credentials, defacing content, or redirecting users to malicious domains. The impact is a breach of confidentiality and integrity for any user of the site, and could also be used to spread malware or phishing pages.

Affected Systems

The vulnerability affects the WP OpenSearch WordPress plugin, all versions from the initial release up to and including version 1.0. The plugin is distributed through the WordPress plugin repository under the vendor name sav.

Risk and Exploitability

The CVSS base score is 7.1, indicating a high severity, while the EPSS score is noted as less than 1 %, suggesting a low probability of exploitation in the short term. The flaw is not currently listed in the CISA KEV catalog. Because the vulnerability is a stored XSS, it can be exploited by an attacker who can inject input that will be persisted and rendered, typically by submitting a form or other user‑generated content on the site. No network isolation or authentication is required beyond access to the site’s content creation interface.

Generated by OpenCVE AI on May 1, 2026 at 17:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP OpenSearch plugin to the latest release whenever an updated version becomes available.
  • If an upgrade cannot be performed immediately, disable the plugin to eliminate the attack surface while a fix is pending.
  • As an interim measure, apply site‑wide input sanitization for all user‑generated content or deploy a web‑application firewall that blocks script tags before content is stored or rendered.

Generated by OpenCVE AI on May 1, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3330 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Savina WP OpenSearch allows Stored XSS. This issue affects WP OpenSearch: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Savina WP OpenSearch allows Stored XSS. This issue affects WP OpenSearch: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sav WP OpenSearch wp-opensearch allows Stored XSS.This issue affects WP OpenSearch: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00035}

epss

{'score': 0.00045}


Mon, 10 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 08:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Savina WP OpenSearch allows Stored XSS. This issue affects WP OpenSearch: from n/a through 1.0.
Title WordPress WP OpenSearch plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:16.503Z

Reserved: 2025-01-16T11:27:59.221Z

Link: CVE-2025-23671

cve-icon Vulnrichment

Updated: 2025-01-31T15:36:28.846Z

cve-icon NVD

Status : Deferred

Published: 2025-01-31T09:15:08.210

Modified: 2026-06-17T08:56:15.977

Link: CVE-2025-23671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T18:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')