Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import allows Stored XSS.This issue affects Blogger Image Import: from 2.1 through n/a.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of input during web page generation, allowing an attacker to store malicious script code that will run in the browsers of users who view the affected content. This is a classic stored XSS flaw, classified under CWE‑79. The attacker can use the plugin’s image import functionality to inject JavaScript that persists after the request completes, enabling a range of browser‑side attacks such as session hijacking or theft of sensitive data. The attack, while not explicitly detailed in the description, is inferred to be facilitated by a CSRF vector that forces a logged‑in user to submit a crafted import request.

Affected Systems

The affected product is the WordPress Blogger Image Import plugin for WordPress sites. Versions up to and including 2.1 are vulnerable; the issue is noted to affect "Blogger Image Import: from 2.1 through n/a," which covers any release equal to or older than 2.1 on WordPress installations that use Poco’s plugin.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability, and the EPSS score of less than 1% shows a low probability of exploitation at present. It is not listed in the CISA KEV catalog. Based on the description, the likely attack path is a remote attacker initiating a CSRF request that causes a privileged user to trigger the import with malicious payloads; no additional privileges or local access are required. Consequently, the risk is moderate to high, but the actual threat level is tempered by the low exploitation likelihood.

Generated by OpenCVE AI on May 1, 2026 at 20:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Blogger Image Import to a version that includes the CVE fix, preferably 2.2 or newer.
  • If an immediate upgrade cannot be performed, disable the image import feature or restrict its use to trusted administrators only to prevent unauthorized submissions.
  • As a temporary workaround, apply server‑side input sanitization to the import fields to strip disallowed scripts before storing them in the database.

Generated by OpenCVE AI on May 1, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3345 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import allows Stored XSS.This issue affects Blogger Image Import: from 2.1 through n/a.
History

Tue, 28 Apr 2026 19:30:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import blogger-image-import allows Stored XSS.This issue affects Blogger Image Import: from n/a through 2.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import allows Stored XSS.This issue affects Blogger Image Import: from 2.1 through n/a.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import allows Stored XSS.This issue affects Blogger Image Import: from 2.1 through n/a. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import blogger-image-import allows Stored XSS.This issue affects Blogger Image Import: from n/a through 2.1.
References

Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import allows Stored XSS.This issue affects Blogger Image Import: from 2.1 through n/a.
Title WordPress Blogger Image Import plugin <= 2.1 - CSRF to Stored XSS vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:17.194Z

Reserved: 2025-01-16T11:28:15.069Z

Link: CVE-2025-23689

cve-icon Vulnrichment

Updated: 2025-01-17T17:19:55.528Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:44.040

Modified: 2026-04-28T19:28:54.927

Link: CVE-2025-23689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:00:08Z

Weaknesses