Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElbowRobo Mass Messaging in BuddyPress mass-messaging-in-buddypress allows Reflected XSS.This issue affects Mass Messaging in BuddyPress: from n/a through <= 2.2.1.
Published: 2025-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that results in a reflected cross‑site scripting flaw. Attackers can inject malicious script code into URLs or form fields processed by the Mass Messaging feature, thus executing arbitrary JavaScript in the victim’s browser. This can lead to session hijacking, defacement, or phishing attacks, directly violating confidentiality, integrity, and availability of the site from the perspective of the affected users. The weakness is a classic input validation failure identified as CWE‑79.

Affected Systems

The plugin affected is ElbowRobo Mass Messaging in BuddyPress, a WordPress plugin that extends BuddyPress functionality. The flaw applies to all releases from the initial release through version 2.2.1 inclusive. Systems running any of these versions are vulnerable and must be updated or disabled to mitigate risk.

Risk and Exploitability

The CVSS base score of 7.1 places this vulnerability in the medium‑to‑high severity range. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis, and the flaw is not listed in the CISA KEV catalog. The most likely attack vector is a reflected XSS scenario through the plugin’s input handling, requiring no special privileges and re‑executing only when a user accesses a crafted URL or submits a malicious form. While the low exploitation probability reduces immediate risk, the impact of a successful attack remains significant, warranting remediation.

Generated by OpenCVE AI on May 2, 2026 at 05:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mass Messaging in BuddyPress to the latest version (≥ 2.2.2) to apply the vendor‑supplied fix.
  • If an upgrade is infeasible, deactivate or remove the Mass Messaging functionality entirely from the WordPress installation.
  • Deploy a Content Security Policy that disallows inline scripts and restricts script sources to mitigate the impact of any residual XSS vectors.

Generated by OpenCVE AI on May 2, 2026 at 05:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3430 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eliott Robson Mass Messaging in BuddyPress allows Reflected XSS. This issue affects Mass Messaging in BuddyPress: from n/a through 2.2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eliott Robson Mass Messaging in BuddyPress allows Reflected XSS. This issue affects Mass Messaging in BuddyPress: from n/a through 2.2.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElbowRobo Mass Messaging in BuddyPress mass-messaging-in-buddypress allows Reflected XSS.This issue affects Mass Messaging in BuddyPress: from n/a through <= 2.2.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 18 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Buddypress
Buddypress buddypress
CPEs cpe:2.3:a:buddypress:buddypress:*:*:*:*:*:wordpress:*:*
Vendors & Products Buddypress
Buddypress buddypress

Wed, 12 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eliott Robson Mass Messaging in BuddyPress allows Reflected XSS. This issue affects Mass Messaging in BuddyPress: from n/a through 2.2.1.
Title WordPress Mass Messaging in BuddyPress Plugin <= 2.2.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Buddypress Buddypress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:20.146Z

Reserved: 2025-01-16T11:30:21.147Z

Link: CVE-2025-23798

cve-icon Vulnrichment

Updated: 2025-01-22T15:25:44.052Z

cve-icon NVD

Status : Modified

Published: 2025-01-22T15:15:23.873

Modified: 2026-04-23T15:24:32.077

Link: CVE-2025-23798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:45:20Z

Weaknesses