Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Leishman WP Easy Post Mailer wp-mailer allows Reflected XSS.This issue affects WP Easy Post Mailer: from n/a through <= 0.64.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper neutralization of input during web page generation in the WordPress WP Easy Post Mailer plugin. A flaw in the way the plugin processes user‑supplied data allows attackers to embed malicious JavaScript that is reflected back in the page. An attacker can inject scripts through crafted URLs or form inputs, which will be executed in the victim’s browser when the vulnerable page is rendered. The impact is the compromise of user session data, defacement, or theft of sensitive information, affecting confidentiality and integrity within the site’s front‑end environment.

Affected Systems

The affected product is the WP Easy Post Mailer plugin developed by Richard Leishman. All versions from the earliest release through version 0.64 are impacted. Users installing any of these versions on a WordPress site are vulnerable if the plugin is active and the related input fields are exposed to untrusted users.

Risk and Exploitability

The assigned CVSS score of 7.1 indicates a high severity, but the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, so there are no documented exploits at this time. The attack vector is likely to be remote, leveraging crafted queries or input fields that result in reflected content. If an attacker can lure a site visitor to a maliciously crafted link, the user’s browser can be tricked into executing arbitrary JavaScript, leading to credential theft, cookie hijacking, or defacement of the web page.

Generated by OpenCVE AI on May 1, 2026 at 14:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Easy Post Mailer plugin to the latest release or a version newer than 0.64
  • If the plugin is no longer required, permanently delete it from the WordPress installation
  • Sanitize and validate all input fields associated with the plugin to prevent unsanitized data from being reflected in output

Generated by OpenCVE AI on May 1, 2026 at 14:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5683 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Easy Post Mailer allows Reflected XSS. This issue affects WP Easy Post Mailer: from n/a through 0.64.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Easy Post Mailer allows Reflected XSS. This issue affects WP Easy Post Mailer: from n/a through 0.64. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Leishman WP Easy Post Mailer wp-mailer allows Reflected XSS.This issue affects WP Easy Post Mailer: from n/a through <= 0.64.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Easy Post Mailer allows Reflected XSS. This issue affects WP Easy Post Mailer: from n/a through 0.64.
Title WordPress WP Easy Post Mailer Plugin <= 0.64 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:54:08.858Z

Reserved: 2025-01-16T11:32:55.400Z

Link: CVE-2025-23956

cve-icon Vulnrichment

Updated: 2025-03-03T15:36:37.430Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:49.010

Modified: 2026-06-17T08:57:47.570

Link: CVE-2025-23956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')