Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tatsuya wp-flickr-press wp-flickr-press allows Reflected XSS.This issue affects wp-flickr-press: from n/a through <= 2.6.4.
Published: 2025-01-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The wp-flickr-press plugin contains an improper neutralization of user input during page generation. This flaw allows an attacker to inject arbitrary JavaScript that is reflected back in the response served to a victim. The injected script runs in the victim’s browser context, and while the description does not specify downstream effects, such code could, in principle, compromise the victim’s session or alter page content. (Based on the description, it is inferred that the impact is the execution of malicious script in users’ browsers.)

Affected Systems

The plugin \"wp-flickr-press\" by developer tatsuya is affected. Any WordPress installation that uses the plugin with version 2.6.4 or earlier is at risk. No fixed version is cited, so all installations of those versions must be considered vulnerable.

Risk and Exploitability

The CVSS score of 7.1 places the vulnerability in the High severity range. The EPSS score below 1% indicates a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker crafting a URL that contains the malicious input; when an end-user follows the link, the reflected script executes in their browser, potentially leading to damage or fraud. This exploitation path requires only the presence of a victim with the vulnerable plugin and a URL containing the reflected payload.

Generated by OpenCVE AI on May 2, 2026 at 05:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade wp-flickr-press to a version newer than 2.6.4 that addresses the reflected XSS flaw.
  • If no patch is available, temporarily remove or disable the plugin to eliminate the vulnerable code.
  • Deploy a web application firewall or enforce a strict Content‑Security‑Policy to block injected scripts and reduce the impact of any remaining XSS vectors.

Generated by OpenCVE AI on May 2, 2026 at 05:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3512 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tatsuya Fukata, Alexander Ovsov wp-flickr-press allows Reflected XSS. This issue affects wp-flickr-press: from n/a through 2.6.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tatsuya Fukata, Alexander Ovsov wp-flickr-press allows Reflected XSS. This issue affects wp-flickr-press: from n/a through 2.6.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tatsuya wp-flickr-press wp-flickr-press allows Reflected XSS.This issue affects wp-flickr-press: from n/a through <= 2.6.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 13 Feb 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tatsuya Fukata, Alexander Ovsov wp-flickr-press allows Reflected XSS. This issue affects wp-flickr-press: from n/a through 2.6.4.
Title WordPress wp-flickr-press Plugin <= 2.6.4 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T23:46:09.376Z

Reserved: 2025-01-16T11:31:51.930Z

Link: CVE-2025-23894

cve-icon Vulnrichment

Updated: 2025-02-12T20:34:10.876Z

cve-icon NVD

Status : Deferred

Published: 2025-01-23T16:15:40.637

Modified: 2026-06-17T08:57:41.367

Link: CVE-2025-23894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:45:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')