Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edem CMC MIGRATE cmc-migrate allows Reflected XSS.This issue affects CMC MIGRATE: from n/a through <= 0.0.3.
Published: 2025-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during page rendering in the Edem CMC MIGRATE plugin allows reflected cross‑site scripting. An attacker can embed malicious script content in a URL, which the plugin then outputs without adequate sanitization, causing the script to execute in the victim’s browser, potentially exposing client‑side data.

Affected Systems

All installations of the WordPress CMC MIGRATE plugin from its first release through version 0.0.3 are affected.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score of < 1% suggests a currently low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is user‑directed web traffic; an attacker must craft a URL containing malicious script payloads that the victim accesses, triggering execution in the browser.

Generated by OpenCVE AI on May 2, 2026 at 09:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the CMC MIGRATE plugin to a version newer than 0.0.3 to remove the identified XSS flaw
  • If an update cannot be applied immediately, deploy a web application firewall or similar solution to block reflected XSS payloads from reaching the browser
  • Audit the plugin’s input handling to confirm that all user‑provided data is properly encoded before rendering, addressing the underlying CWE‑79 weakness

Generated by OpenCVE AI on May 2, 2026 at 09:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3384 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound CMC MIGRATE allows Reflected XSS. This issue affects CMC MIGRATE: from n/a through 0.0.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound CMC MIGRATE allows Reflected XSS. This issue affects CMC MIGRATE: from n/a through 0.0.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edem CMC MIGRATE cmc-migrate allows Reflected XSS.This issue affects CMC MIGRATE: from n/a through <= 0.0.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 22 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound CMC MIGRATE allows Reflected XSS. This issue affects CMC MIGRATE: from n/a through 0.0.3.
Title WordPress CMC MIGRATE plugin <= 0.0.3 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:07:07.889Z

Reserved: 2025-01-16T11:29:28.684Z

Link: CVE-2025-23746

cve-icon Vulnrichment

Updated: 2025-01-22T15:10:10.463Z

cve-icon NVD

Status : Deferred

Published: 2025-01-22T15:15:22.783

Modified: 2026-06-17T08:56:52.480

Link: CVE-2025-23746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:45:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')