Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Reflected XSS.This issue affects TotalContest Lite: from n/a through <= 2.8.1.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an instance of Improper Neutralization of Input During Web Page Generation, which enables reflected Cross‑Site Scripting. Attackers can embed malicious scripts into a URL or form that TotalContest Lite echoes back to users. The injected payload can execute in the victim’s browser, potentially stealing session cookies, defacing content, or redirecting users to phishing sites. This weakness is identified as CWE‑79.

Affected Systems

TotalSuite’s TotalContest Lite plugin for WordPress is affected. All releases from the earliest available version up through 2.8.1 contain the flaw. Users running any of these versions on a WordPress site are susceptible.

Risk and Exploitability

The CVSS score of 7.1 classifies this as a high‑severity vulnerability, while the EPSS score of < 1 % indicates a very low probability of exploitation in the wild. At present the vulnerability is not listed in CISA’s KEV catalog, suggesting no active exploitation campaigns. The flaw can be exploited remotely by delivering a crafted payload via an HTTP request that includes vulnerable parameters, and the victim reconstructs the malicious script in the browser. Because the supplied payload is reflected, an attacker only needs a link or an embedded form to trigger execution, making the attack relatively straightforward for an adversary with a basic knowledge of XSS.

Generated by OpenCVE AI on May 2, 2026 at 01:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the TotalContest Lite plugin to the latest available version, ensuring the XSS fix is applied.
  • If a newer version is not available, deactivate or delete the TotalContest Lite plugin to prevent the vulnerability from being exposed.
  • After applying the fix, perform a quick XSS test by loading a page with a crafted query string to confirm that malicious scripts are no longer executed.

Generated by OpenCVE AI on May 2, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11591 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TotalSuite TotalContest Lite allows Reflected XSS. This issue affects TotalContest Lite: from n/a through 2.8.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TotalSuite TotalContest Lite allows Reflected XSS. This issue affects TotalContest Lite: from n/a through 2.8.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Reflected XSS.This issue affects TotalContest Lite: from n/a through <= 2.8.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TotalSuite TotalContest Lite allows Reflected XSS. This issue affects TotalContest Lite: from n/a through 2.8.1.
Title WordPress TotalContest Lite Plugin <= 2.8.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T23:59:36.576Z

Reserved: 2025-01-16T11:30:13.733Z

Link: CVE-2025-23782

cve-icon Vulnrichment

Updated: 2025-04-17T17:42:49.871Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:30.620

Modified: 2026-06-17T08:57:09.817

Link: CVE-2025-23782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T02:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')