Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gavin Affiliate Tools Việt Nam affiliate-tools-viet-nam allows Reflected XSS.This issue affects Affiliate Tools Việt Nam: from n/a through <= 0.3.17.
Published: 2025-01-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a reflected cross‑site scripting flaw caused by improper neutralization of user input during web page generation. The flaw allows an attacker to inject arbitrary HTML or JavaScript that is reflected back to the victim’s browser. Based on the description, it is inferred that an attacker could exploit this to compromise user sessions or execute malicious code within the victim’s context.

Affected Systems

The affected product is the Gavin Affiliate Tools Việt Nam WordPress plugin, with all versions from unspecified earlier releases up to and including 0.3.17 being vulnerable. The plugin is used as a WordPress extension, and any WordPress installation that has a vulnerable version installed is susceptible.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates a very low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known malicious exploitation at this time. It is inferred that exploitation would require an attacker to deliver a crafted input—such as a specially formed URL or form submission—that is reflected in the page, enabling malicious JavaScript to run in the victim’s browser. The impact is confined to the victim’s client side and does not directly compromise the server.

Generated by OpenCVE AI on May 2, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Gavin Affiliate Tools Việt Nam plugin to any release newer than 0.3.17.
  • If an update is not available or the plugin is unnecessary, deactivate or uninstall it to eliminate the exposure.
  • Apply a Content Security Policy that blocks inline scripts or restricts script sources to trusted domains to mitigate the impact of any reflected XSS payloads.

Generated by OpenCVE AI on May 2, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3395 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leduchuy89vn Affiliate Tools Việt Nam allows Reflected XSS. This issue affects Affiliate Tools Việt Nam: from n/a through 0.3.17.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leduchuy89vn Affiliate Tools Việt Nam allows Reflected XSS. This issue affects Affiliate Tools Việt Nam: from n/a through 0.3.17. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gavin Affiliate Tools Việt Nam affiliate-tools-viet-nam allows Reflected XSS.This issue affects Affiliate Tools Việt Nam: from n/a through <= 0.3.17.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00035}

epss

{'score': 0.00045}


Mon, 10 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 08:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leduchuy89vn Affiliate Tools Việt Nam allows Reflected XSS. This issue affects Affiliate Tools Việt Nam: from n/a through 0.3.17.
Title WordPress Affiliate Tools Việt Nam plugin <= 0.3.17 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:18.885Z

Reserved: 2025-01-16T11:29:46.483Z

Link: CVE-2025-23759

cve-icon Vulnrichment

Updated: 2025-01-31T15:36:26.038Z

cve-icon NVD

Status : Deferred

Published: 2025-01-31T09:15:08.357

Modified: 2026-06-17T08:56:58.770

Link: CVE-2025-23759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:30:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')