Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyljp SpiderDisplay spiderdisplay allows Reflected XSS.This issue affects SpiderDisplay: from n/a through <= 1.9.1.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw is an Improper Neutralization of Input During Web Page Generation vulnerability that permits a reflected XSS bug in the SpiderDisplay plugin for WordPress. It allows an attacker to inject malicious JavaScript or HTML into pages that are displayed to users. By causing unintended script execution the attacker can hijack user sessions, steal login credentials, or perform phishing attacks against visitors. The weakness is a classic input validation issue classified as CWE‑79.

Affected Systems

WordPress sites that use the SPIDERDISPLAY plugin from any version up to and including 1.9.1 are vulnerable. The plugin is listed under the vendor 'fyljp' with the product name SpiderDisplay. If a site runs SpiderDisplay 1.9.1 or earlier it is affected; no other WordPress core or plugin versions are implicated by this entry.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity exposure in the medium‑to‑high risk range, but the EPSS score of less than 1% shows a very low likelihood of active exploitation at the time of analysis. The flaw is not in the CISA KEV catalog. Based on the description the likely attack vector is a reflected XSS scenario, where an attacker crafts a malicious URL or form input that, when opened by another user, executes arbitrary JavaScript. It requires a victim to visit the distorted URL or submit a forged form, so the attack needs user interaction but can be carried out through any public or internal web page that loads the plugin.

Generated by OpenCVE AI on May 1, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update SpiderDisplay to the latest released version (≥1.9.2 or newer) since the vulnerability was fixed after 1.9.1.
  • If an immediate upgrade is not possible, block or filter all user‑supplied parameters that are processed by SpiderDisplay using a web application firewall or content‑security policy to prevent script execution.
  • Review and enforce strict input validation and output encoding on any custom fields or shortcodes that the plugin processes, ensuring data is properly neutralized before rendering.

Generated by OpenCVE AI on May 1, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11592 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyljp SpiderDisplay allows Reflected XSS. This issue affects SpiderDisplay: from n/a through 1.9.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyljp SpiderDisplay allows Reflected XSS. This issue affects SpiderDisplay: from n/a through 1.9.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyljp SpiderDisplay spiderdisplay allows Reflected XSS.This issue affects SpiderDisplay: from n/a through <= 1.9.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyljp SpiderDisplay allows Reflected XSS. This issue affects SpiderDisplay: from n/a through 1.9.1.
Title WordPress SpiderDisplay plugin <= 1.9.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T23:59:07.691Z

Reserved: 2025-01-16T11:31:13.711Z

Link: CVE-2025-23855

cve-icon Vulnrichment

Updated: 2025-04-17T17:42:54.361Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:30.773

Modified: 2026-06-17T08:57:37.490

Link: CVE-2025-23855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T09:30:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')