Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wassereimer Easy Code Placement allows Reflected XSS. This issue affects Easy Code Placement: from n/a through 18.11.
Published: 2025-02-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an Improper Neutralization of Input During Web Page Generation, allowing attackers to inject malicious scripts that are reflected back to the victim’s browser. Attackers could trick users into visiting a crafted URL that contains arbitrary JavaScript, leading to malicious code execution, theft of credentials, session hijacking, or defacement of the site. The weakness is a classic reflected Cross‑Site Scripting flaw, aligning with CWE‑79.

Affected Systems

The Easy Code Placement plugin from the WordPress ecosystem, maintained by wusserheimer, is affected. Any installation running the plugin at version 18.11 or older is vulnerable, and, per the vendor, any version from the original release (n/a) up through 18.11 is susceptible.

Risk and Exploitability

The EPSS score indicates less than 1% probability that this vulnerability will be exploited in the wild, and it is not listed in the CISA KEV catalog, suggesting low current exploitation activity. The attack vector most likely relies on a maliciously crafted request that leverages the plugin’s code rendering endpoint, requiring the victim to click a link or visit a URL in a browser. Because the flaw is remote and reflects user input without sanitization, it can be exploited without additional authentication or local access, elevating the risk especially on sites that allow untrusted users to submit code via the plugin.

Generated by OpenCVE AI on May 1, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Easy Code Placement plugin to the latest released version that contains the XSS fix.
  • If an immediate update is not possible, disable the plugin or remove any instances that accept untrusted code to prevent reflected attacks.
  • Implement a strict Content Security Policy that limits script execution and whitelists trusted sources to mitigate the impact of any reflected XSS attempts.

Generated by OpenCVE AI on May 1, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3422 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wassereimer Easy Code Placement allows Reflected XSS. This issue affects Easy Code Placement: from n/a through 18.11.
History

Tue, 28 Apr 2026 19:30:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wassereimer Easy Code Placement easy-code-placement allows Reflected XSS.This issue affects Easy Code Placement: from n/a through <= 18.11. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wassereimer Easy Code Placement allows Reflected XSS. This issue affects Easy Code Placement: from n/a through 18.11.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wassereimer Easy Code Placement allows Reflected XSS. This issue affects Easy Code Placement: from n/a through 18.11. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wassereimer Easy Code Placement easy-code-placement allows Reflected XSS.This issue affects Easy Code Placement: from n/a through <= 18.11.
References

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00032}

epss

{'score': 0.00035}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00072}

epss

{'score': 0.00032}


Fri, 14 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Feb 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wassereimer Easy Code Placement allows Reflected XSS. This issue affects Easy Code Placement: from n/a through 18.11.
Title WordPress Easy Code Placement Plugin <= 18.11 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:20.159Z

Reserved: 2025-01-16T11:30:13.734Z

Link: CVE-2025-23790

cve-icon Vulnrichment

Updated: 2025-02-14T15:35:20.604Z

cve-icon NVD

Status : Deferred

Published: 2025-02-14T13:15:47.417

Modified: 2026-04-28T19:29:00.907

Link: CVE-2025-23790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T16:30:20Z

Weaknesses