Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tony Hayes Guten Free Options guten-free-options allows Reflected XSS.This issue affects Guten Free Options: from n/a through <= 0.9.7.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the WordPress Guten Free Options plugin, where user-supplied data is not properly neutralized before being included in dynamically generated web pages. This flaw enables a reflected cross‑site scripting (XSS) attack that can be exploited to inject and execute arbitrary JavaScript within the victim's browser. Such an attack can compromise user sessions, steal credentials, deface content, or deliver phishing payloads.

Affected Systems

The flaw affects the Guten Free Options plugin distributed by Tony Hayes. All releases from the earliest version up to and including 0.9.7 are vulnerable. Sites running any of those plugin versions are at risk.

Risk and Exploitability

The CVSS score of 7.1 signifies a high‑severity vulnerability that can be triggered remotely by delivering a crafted request to the affected plugin. The EPSS score of less than 1% indicates that currently there is a low probability of exploitation in the wild, and the vulnerability has not been listed in the CISA KEV catalog. Nonetheless, because the flaw permits reflected XSS, an attacker could potentially execute malicious JavaScript in the context of the target site’s users without requiring prior authentication. The most likely path involves sending a malicious link or embedding a forged form that includes unsafe script content, which the plugin then renders into the page without sanitization.

Generated by OpenCVE AI on May 1, 2026 at 14:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Guten Free Options plugin to the latest version (at least 0.9.8) that includes the input sanitization fix.
  • If an upgrade cannot be performed immediately, deactivate or remove the plugin from the WordPress installation to eliminate the vulnerable code path.
  • Until the plugin is updated or disabled, apply a web application firewall rule or client‑side Content‑Security‑Policy that blocks or sanitizes injected scripts to mitigate the reflected XSS impact.

Generated by OpenCVE AI on May 1, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5687 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Guten Free Options allows Reflected XSS. This issue affects Guten Free Options: from n/a through 0.9.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Guten Free Options allows Reflected XSS. This issue affects Guten Free Options: from n/a through 0.9.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tony Hayes Guten Free Options guten-free-options allows Reflected XSS.This issue affects Guten Free Options: from n/a through <= 0.9.7.
Title WordPress Guten Free Options Plugin <= 0.9.5 - Reflected Cross Site Scripting (XSS) vulnerability WordPress Guten Free Options Plugin <= 0.9.7 - Reflected Cross Site Scripting (XSS) vulnerability
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Guten Free Options allows Reflected XSS. This issue affects Guten Free Options: from n/a through 0.9.5.
Title WordPress Guten Free Options Plugin <= 0.9.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:20.992Z

Reserved: 2025-01-16T11:30:44.311Z

Link: CVE-2025-23813

cve-icon Vulnrichment

Updated: 2025-03-03T19:10:42.470Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:47.140

Modified: 2026-04-23T15:24:33.733

Link: CVE-2025-23813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:45:16Z

Weaknesses