Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xdxdVSxdxd MACME macme allows Reflected XSS.This issue affects MACME: from n/a through <= 1.2.
Published: 2025-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper handling of user input in the MACME plugin allows arbitrary script code to be reflected back to the user in a web page, creating an XSS vulnerability (CWE‑79). The flaw permits an attacker to craft a URL containing malicious script which, when opened by a victim, runs in the victim’s browser context. This can lead to session hijacking, cookie theft, defacement or the execution of further attacks within the user’s session. The CVSS base score of 7.1 highlights that the XSS can be used for significant impact while requiring only user interaction.

Affected Systems

The MACME WordPress plugin from vendor xdxdVSxdxd is vulnerable in all copies whose version number is 1.2 or earlier. No specific earlier versions are listed, so every release up to and including 1.2 is affected. The plugin is identified by the vendor name and product title.

Risk and Exploitability

The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation in the wild, while the vulnerability is not currently included in CISA’s KEV catalog. Exploitation requires an attacker to entice a user to click a malicious link that contains a payload targeting the plugin’s reflected input handling. Because the flaw resides entirely on the client side, an attacker can execute it from any location; however, successful exploitation still depends on the victim’s interaction with the crafted URL. The moderate severity score reflects that, once executed, the attacker gains the user’s browser privileges, which can be leveraged for further attacks.

Generated by OpenCVE AI on May 1, 2026 at 19:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MACME plugin to the latest released version (1.3 or newer) which removes the reflected input flaw
  • If an update is not immediately available, temporarily deactivate the plugin or replace it with an alternative that correctly sanitizes user input
  • Configure a web application firewall or use server‑side filters to block or escape any script characters that may be injected through query parameters
  • Audit all pages that use the plugin to ensure no user‑supplied content is reflected without proper escaping

Generated by OpenCVE AI on May 1, 2026 at 19:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3341 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MACME allows Reflected XSS. This issue affects MACME: from n/a through 1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MACME allows Reflected XSS. This issue affects MACME: from n/a through 1.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xdxdVSxdxd MACME macme allows Reflected XSS.This issue affects MACME: from n/a through <= 1.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 22 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MACME allows Reflected XSS. This issue affects MACME: from n/a through 1.2.
Title WordPress MACME plugin <= 1.2 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:17.037Z

Reserved: 2025-01-16T11:28:15.067Z

Link: CVE-2025-23683

cve-icon Vulnrichment

Updated: 2025-01-22T16:16:13.146Z

cve-icon NVD

Status : Deferred

Published: 2025-01-22T15:15:21.260

Modified: 2026-06-17T08:56:21.660

Link: CVE-2025-23683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:45:24Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')