Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sayoko SC Simple Zazzle sc-simple-zazzle allows Reflected XSS.This issue affects SC Simple Zazzle: from n/a through <= 1.1.6.
Published: 2025-01-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation in the SC Simple Zazzle WordPress plugin allows attackers to inject arbitrary JavaScript that is reflected back to the victim’s browser. This reflected XSS flaw is classified as CWE‑79 and can enable an attacker to execute code in the context of a logged‑in user, potentially stealing session cookies, hijacking user sessions, defacing sites or injecting additional malicious payloads.

Affected Systems

The vulnerability affects the SC Simple Zazzle plugin developed by sayoko for WordPress, with all releases from the earliest available through version 1.1.6 being susceptible. No other vendors or products are mentioned as affected.

Risk and Exploitability

The CVSS score of 7.1 places the issue in the high‑severity range, indicating that successful exploitation could severely affect confidentiality, integrity, or availability of the user session. The EPSS score of less than 1 % points to a low probability of current exploitation, though not zero. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a reflected XSS that requires a victim to visit a crafted URL or submit data that the plugin incorrectly echoes. An attacker must supply the malicious input, which is then reflected in the page output, enabling script execution in the victim’s browser. The vulnerability does not appear to have any special network‑level prerequisites beyond web traffic to the affected plugin.

Generated by OpenCVE AI on May 1, 2026 at 19:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SC Simple Zazzle plugin to a version newer than 1.1.6, which removes the reflected XSS flaw.
  • If an upgrade is not feasible, disable or remove the SC Simple Zazzle plugin from the WordPress installation to eliminate the attack surface.
  • Deploy a Web Application Firewall or set appropriate Content Security Policy rules to mitigate the impact of any remaining reflected XSS vectors by restricting script execution and blocking inline scripts.

Generated by OpenCVE AI on May 1, 2026 at 19:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3378 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sayocode SC Simple Zazzle allows Reflected XSS. This issue affects SC Simple Zazzle: from n/a through 1.1.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sayocode SC Simple Zazzle allows Reflected XSS. This issue affects SC Simple Zazzle: from n/a through 1.1.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sayoko SC Simple Zazzle sc-simple-zazzle allows Reflected XSS.This issue affects SC Simple Zazzle: from n/a through <= 1.1.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sayocode SC Simple Zazzle allows Reflected XSS. This issue affects SC Simple Zazzle: from n/a through 1.1.6.
Title WordPress SC Simple Zazzle plugin <= 1.1.6 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:18.400Z

Reserved: 2025-01-16T11:29:21.050Z

Link: CVE-2025-23733

cve-icon Vulnrichment

Updated: 2025-02-12T20:34:22.285Z

cve-icon NVD

Status : Deferred

Published: 2025-01-23T16:15:40.073

Modified: 2026-06-17T08:56:46.340

Link: CVE-2025-23733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:15:24Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')