Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bannersky BSK Forms Validation bsk-gravity-forms-custom-validation allows Reflected XSS.This issue affects BSK Forms Validation: from n/a through <= 1.7.
Published: 2025-02-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The BSK Forms Validation plugin contains an Improper Neutralization of Input During Web Page Generation (CWE‑79) flaw that allows reflected XSS. When users submit form data that is not properly sanitized, the input is echoed back into the page, enabling an attacker to embed malicious JavaScript. An attacker can use this to hijack sessions, steal credentials, or deface the site. The vulnerability is limited to the plugin’s form processing logic and does not grant direct server access, but it can have severe client‑side consequences. The attack requires only a crafted request and the victim’s browser rendering the response.

Affected Systems

Bannersky’s BSK Forms Validation plugin, WordPress sites that have installed the plugin in any version up to and including 1.7. No other vendors or products are affected.

Risk and Exploitability

The CVSS score of 7.1 indicates high risk with moderate complexity and requires user interaction. The EPSS score is less than 1%, suggesting that active exploitation in the wild is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog, so there is no known mass exploitation campaign. An attacker can exploit the flaw by sending a specially crafted form submission with a malicious payload that will be reflected in the resulting page. The attacker only needs to entice a user to visit or submit that form; no additional privileges or system access are required.

Generated by OpenCVE AI on May 1, 2026 at 17:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the BSK Forms Validation plugin to the latest released version (1.8 or later).
  • Add server‑side output encoding (e.g., htmlspecialchars) to all form fields that echo user input.
  • Deploy a web application firewall rule that blocks common XSS payloads in form submissions.

Generated by OpenCVE AI on May 1, 2026 at 17:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3756 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BannerSky.com BSK Forms Validation allows Reflected XSS. This issue affects BSK Forms Validation: from n/a through 1.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BannerSky.com BSK Forms Validation allows Reflected XSS. This issue affects BSK Forms Validation: from n/a through 1.7. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bannersky BSK Forms Validation bsk-gravity-forms-custom-validation allows Reflected XSS.This issue affects BSK Forms Validation: from n/a through <= 1.7.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00035}

epss

{'score': 0.00045}


Mon, 03 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BannerSky.com BSK Forms Validation allows Reflected XSS. This issue affects BSK Forms Validation: from n/a through 1.7.
Title WordPress BSK Forms Validation plugin <= 1.7 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:28.239Z

Reserved: 2025-01-23T14:50:18.328Z

Link: CVE-2025-24545

cve-icon Vulnrichment

Updated: 2025-02-03T16:06:33.665Z

cve-icon NVD

Status : Deferred

Published: 2025-02-03T15:15:24.177

Modified: 2026-06-17T08:59:12.300

Link: CVE-2025-24545

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T17:45:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')