Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jmraya Legal + legal-plus allows Reflected XSS.This issue affects Legal +: from n/a through <= 1.0.
Published: 2025-01-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Reflected Cross‑Site Scripting flaw caused by improper input neutralization during web page generation in the Legal + plugin. When user input is reflected back in the browser without adequate sanitization, malicious JavaScript can execute in the victim’s browser context. This exposure can lead to cookie theft, session hijacking, or defacement of the web page, thereby compromising the confidentiality and integrity of user sessions. The weakness is identified as CWE‑79.

Affected Systems

The plugin jmraya Legal + is affected for all releases from the initial version up to and including version 1.0. Any WordPress installation running any version of Legal + through 1.0 is vulnerable.

Risk and Exploitability

With a CVSS score of 7.1, the flaw has moderate to high severity. The EPSS score of less than 1% indicates that exploitation is unlikely to be widespread, and the issue is not currently listed in the CISA KEV catalog. The attack vector is inferred to be remote, via a malicious URL or link that includes crafted query parameters or form input that is reflected by the plugin. Any authenticated or unauthenticated user who navigates to the vulnerable endpoint could be targeted, making this a broad‑scope client‑side threat that does not require elevated privileges.

Generated by OpenCVE AI on May 1, 2026 at 19:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Legal + plugin to the latest version that contains the XSS fix.
  • If an update is not immediately available, disable or remove the Legal + plugin from the site to eliminate the vulnerability.
  • Deploy or configure a web application firewall to detect and block malicious script payloads targeting the plugin’s input fields.

Generated by OpenCVE AI on May 1, 2026 at 19:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3464 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Legal + allows Reflected XSS. This issue affects Legal +: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Legal + allows Reflected XSS. This issue affects Legal +: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jmraya Legal + legal-plus allows Reflected XSS.This issue affects Legal +: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Legal + allows Reflected XSS. This issue affects Legal +: from n/a through 1.0.
Title WordPress Legal + Plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:22.125Z

Reserved: 2025-01-16T11:30:58.639Z

Link: CVE-2025-23835

cve-icon Vulnrichment

Updated: 2025-02-12T20:34:16.907Z

cve-icon NVD

Status : Deferred

Published: 2025-01-23T16:15:40.353

Modified: 2026-06-17T08:57:35.480

Link: CVE-2025-23835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:15:24Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')