Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foo123 Top Flash Embed top-flash-embed allows Stored XSS.This issue affects Top Flash Embed: from n/a through <= 0.3.4.
Published: 2025-01-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Top Flash Embed plugin fails to neutralize user‑supplied content before rendering it in web pages, resulting in a stored cross‑site scripting flaw (CWE‑79). This vulnerability allows malicious JavaScript to be stored through the plugin’s input mechanisms and then executed in the browsers of any visitor to a page that displays that stored content.

Affected Systems

The vulnerability impacts foo123’s Top Flash Embed WordPress plugin, version 0.3.4 and all earlier releases. Sites that have any of these versions installed are susceptible.

Risk and Exploitability

With a CVSS score of 6.5, the flaw poses a moderate severity risk. The EPSS score of <1% indicates a low current probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers would likely exploit the plugin's data input mechanisms, inserting malicious scripts into stored content that is subsequently rendered for site visitors.

Generated by OpenCVE AI on May 2, 2026 at 09:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Top Flash Embed to a version that fixes the XSS flaw.
  • Disable the Top Flash Embed plugin or delete all stored content that could contain malicious scripts until a patched version is available.
  • Implement a web application firewall rule that blocks malicious script injections on the plugin’s input forms or in stored content.

Generated by OpenCVE AI on May 2, 2026 at 09:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3469 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikos M. Top Flash Embed allows Stored XSS.This issue affects Top Flash Embed: from n/a through 0.3.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikos M. Top Flash Embed allows Stored XSS.This issue affects Top Flash Embed: from n/a through 0.3.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foo123 Top Flash Embed top-flash-embed allows Stored XSS.This issue affects Top Flash Embed: from n/a through <= 0.3.4.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikos M. Top Flash Embed allows Stored XSS.This issue affects Top Flash Embed: from n/a through 0.3.4.
Title WordPress Top Flash Embed plugin <= 0.3.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:22.185Z

Reserved: 2025-01-16T11:30:58.639Z

Link: CVE-2025-23841

cve-icon Vulnrichment

Updated: 2025-01-17T17:17:59.288Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:24.793

Modified: 2026-06-17T08:57:36.080

Link: CVE-2025-23841

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:45:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')