Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ivobrett Apply with LinkedIn buttons apply-with-linkedin-buttons allows DOM-Based XSS.This issue affects Apply with LinkedIn buttons: from n/a through <= 2.3.
Published: 2025-01-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Apply with LinkedIn buttons plugin for WordPress contains an improper neutralization of input during web page generation, which allows a DOM‑based Cross‑Site Scripting (XSS) flaw. This flaw means that unescaped user‑supplied data can be rendered by the browser, enabling an attacker to execute arbitrary JavaScript in the context of any user who views the affected page. The directly stated impact is potential client‑side script execution that can modify the page view or carry out actions on behalf of the user.

Affected Systems

WordPress sites that have ivobrett’s Apply with LinkedIn buttons plugin installed in any version from its initial release through 2.3 (inclusive) are susceptible. The vulnerability exists in the plugin’s front‑end rendering code and does not require administrative privileges on the site.

Risk and Exploitability

With a CVSS score of 6.5 the flaw presents a moderate risk. The EPSS score of less than 1 % and the fact that the vulnerability is not recorded in the CISA KEV catalog suggest that widespread exploitation is unlikely at this time. Based on the nature of DOM‑based XSS, the likely attack vector is a maliciously crafted web page or link that the user visits, which could be delivered through social engineering or embedding on a third‑party site; this inference is drawn from the requirement that the browser must render the vulnerable code.

Generated by OpenCVE AI on May 2, 2026 at 06:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ivobrett Apply with LinkedIn buttons plugin to any version newer than 2.3 if a fix is available.
  • If an upgrade is not possible, deactivate or uninstall the plugin to remove the vulnerability.
  • Implement a Content Security Policy that restricts the execution of inline scripts and blocks untrusted external scripts, to mitigate the impact of any residual XSS risk.

Generated by OpenCVE AI on May 2, 2026 at 06:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3515 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ivo Brett – ApplyMetrics Apply with LinkedIn buttons allows DOM-Based XSS.This issue affects Apply with LinkedIn buttons: from n/a through 2.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ivo Brett – ApplyMetrics Apply with LinkedIn buttons allows DOM-Based XSS.This issue affects Apply with LinkedIn buttons: from n/a through 2.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ivobrett Apply with LinkedIn buttons apply-with-linkedin-buttons allows DOM-Based XSS.This issue affects Apply with LinkedIn buttons: from n/a through <= 2.3.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ivo Brett – ApplyMetrics Apply with LinkedIn buttons allows DOM-Based XSS.This issue affects Apply with LinkedIn buttons: from n/a through 2.3.
Title WordPress Apply with LinkedIn buttons plugin <= 2.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:24.201Z

Reserved: 2025-01-16T11:31:51.931Z

Link: CVE-2025-23897

cve-icon Vulnrichment

Updated: 2025-01-17T17:16:28.715Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:31.310

Modified: 2026-06-17T08:57:41.670

Link: CVE-2025-23897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')