Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saill Site Launcher site-launcher allows Reflected XSS.This issue affects Site Launcher: from n/a through <= 0.9.4.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability originates from improper neutralization of input during web page generation in the Site Launcher plugin. A malicious actor can embed script content into reflected parameters, causing the plugin to render the payload in the page. When users visit the crafted URL, the script runs in the context of the site, potentially allowing attackers to steal session cookies, manipulate page content, or redirect users to phishing sites. The weakness is classified as CWE‑79, a classic reflected XSS flaw.

Affected Systems

The affected product is the Site Launcher plugin developed by saill. All releases from the earliest version up through 0.9.4 are vulnerable, meaning any installation of 0.9.4 or earlier is at risk. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate severity, while the EPSS score of less than 1% reflects a low probability of widespread exploitation at this time. The vulnerability is not catalogued in the CISA KEV list. Exploitation would likely proceed via a crafted URL that includes malicious script payloads, which is easily reproducible by attackers with minimal resources. If successful, the impact would be limited to browsers of visitors who click the link, but the damage can be significant for sites with high traffic, including credential theft and user defacement.

Generated by OpenCVE AI on May 2, 2026 at 03:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for the latest version of the Site Launcher plugin and upgrade if available.
  • If an upgrade is not immediately possible, disable or uninstall the plugin to remove the reflected XSS entry point.
  • As a temporary measure, apply strict Content Security Policy headers that block inline scripts and enable script whitelisting, and ensure that all user‑supplied data is escaped before rendering in the page.

Generated by OpenCVE AI on May 2, 2026 at 03:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5685 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Site Launcher allows Reflected XSS. This issue affects Site Launcher: from n/a through 0.9.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Site Launcher allows Reflected XSS. This issue affects Site Launcher: from n/a through 0.9.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saill Site Launcher site-launcher allows Reflected XSS.This issue affects Site Launcher: from n/a through <= 0.9.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Site Launcher allows Reflected XSS. This issue affects Site Launcher: from n/a through 0.9.4.
Title WordPress Site Launcher Plugin <= 0.9.4 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:50:43.202Z

Reserved: 2025-01-16T11:31:05.973Z

Link: CVE-2025-23847

cve-icon Vulnrichment

Updated: 2025-03-03T18:42:14.522Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:47.730

Modified: 2026-06-17T08:57:36.687

Link: CVE-2025-23847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')