Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeglow Cleanup – Directory Listing & Classifieds WordPress Plugin cleanup-light allows Reflected XSS.This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through <= 1.0.4.
Published: 2025-01-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of Input During Web Page Generation in the themeglow Cleanup – Directory Listing & Classifieds WordPress Plugin allows an attacker to inject malicious script into pages that are rendered to end users. This reflected cross‑site scripting flaw (CWE‑79) can lead to session hijacking, defacement, or delivery of malware when a victim visits a crafted URL containing malicious JavaScript. The vulnerability is triggered by unsanitized input that the plugin echoes back in the generated web content.

Affected Systems

All installations of the cleanup‑light plugin version 1.0.4 or earlier on any WordPress site are vulnerable. The affected product is the themeglow Cleanup – Directory Listing & Classifieds WordPress Plugin, with the vulnerability impacting all versions released up to 1.0.4. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 7.1 classifies this as a moderate to high severity flaw, but the EPSS score of less than 1 % indicates a very low current exploitation probability in real-world attacks. The flaw is listed as not present in the CISA KEV catalog. The likely attack vector is a remote web request that contains a specially crafted parameter; the attacker does not need local privileges, though the victim must interact with the vulnerable page. Because the flaw works through reflected input, it may be exploitable via social engineering or malicious links. Despite the low EPSS, the potential for damaging XSS impacts warrants prompt remediation.

Generated by OpenCVE AI on May 1, 2026 at 17:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the cleanup‑light plugin to a version newer than 1.0.4 that removes the XSS flaw.
  • If an update is not immediately available, temporarily disable the plugin or restrict access to its pages until the issue is resolved.
  • Apply a web application firewall rule or use a security plugin to filter or block JavaScript payloads that target the plugin's input fields.

Generated by OpenCVE AI on May 1, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3771 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGlow Cleanup – Directory Listing & Classifieds WordPress Plugin allows Reflected XSS. This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through 1.0.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGlow Cleanup – Directory Listing & Classifieds WordPress Plugin allows Reflected XSS. This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through 1.0.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeglow Cleanup – Directory Listing & Classifieds WordPress Plugin cleanup-light allows Reflected XSS.This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through <= 1.0.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00035}

epss

{'score': 0.00045}


Mon, 10 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 08:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGlow Cleanup – Directory Listing & Classifieds WordPress Plugin allows Reflected XSS. This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through 1.0.4.
Title WordPress Cleanup – Directory Listing & Classifieds plugin <= 1.0.4 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:25:08.888Z

Reserved: 2025-01-23T14:50:32.998Z

Link: CVE-2025-24563

cve-icon Vulnrichment

Updated: 2025-01-31T15:36:07.960Z

cve-icon NVD

Status : Deferred

Published: 2025-01-31T09:15:10.467

Modified: 2026-06-17T08:59:14.077

Link: CVE-2025-24563

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T18:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')