Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ketchup Shortcodes ketchup-shortcodes-pack allows Stored XSS.This issue affects Ketchup Shortcodes: from n/a through <= 0.1.2.
Published: 2025-01-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of script‑related HTML tags in the Ketchup Shortcodes plugin enables a stored cross‑site scripting (XSS) vulnerability. Attacking input that includes JavaScript or other malicious content can be saved in a post or shortcode, then executed in the browsers of any user who views the affected content. This allows an attacker to steal session cookies, deface content, or redirect victims, thereby compromising confidentiality and integrity of the web site.

Affected Systems

The flaw affects the AyeCode Ketchup Shortcodes plugin for WordPress through version 0.1.2. All installations using any earlier release of the plugin are potentially impacted. The vendor is AyeCode, and the product name is Ketchup Shortcodes. No specific sub‑product or platform constraints were listed, so any WordPress installation including this plugin is vulnerable.

Risk and Exploitability

The CVSS base score of 6.5 classifies the weakness as moderate severity, and the EPSS score of less than 1 % indicates a very low but non‑zero probability of exploitation in the wild. The vulnerability is not currently listed in CISA’s KEV catalogue, suggesting no recorded, widespread exploits. However, because the attack requires only the injection of content that is stored and later rendered, a single compromised account or malicious post can trigger the payload. Countermeasures are effective if a patch is applied promptly, and the risk is mitigated by disabling or removing the plugin if an update is unavailable.

Generated by OpenCVE AI on May 1, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest version of the Ketchup Shortcodes plugin (≥ 0.1.3) once it becomes available.
  • If an upgrade is not immediately possible, temporarily deactivate or delete the plugin to prevent the execution of stored XSS payloads.
  • Sanitize existing content containing shortcode input, or employ a content‑safety plugin that filters script tags from post editors.

Generated by OpenCVE AI on May 1, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3867 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ltd Ketchup Shortcodes allows Stored XSS. This issue affects Ketchup Shortcodes: from n/a through 0.1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ltd Ketchup Shortcodes allows Stored XSS. This issue affects Ketchup Shortcodes: from n/a through 0.1.2. Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ketchup Shortcodes ketchup-shortcodes-pack allows Stored XSS.This issue affects Ketchup Shortcodes: from n/a through <= 0.1.2.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ltd Ketchup Shortcodes allows Stored XSS. This issue affects Ketchup Shortcodes: from n/a through 0.1.2.
Title WordPress Ketchup Shortcodes Plugin <= 0.1.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:31.671Z

Reserved: 2025-01-23T14:52:05.566Z

Link: CVE-2025-24673

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-01-24T18:15:41.033

Modified: 2026-04-23T15:25:15.687

Link: CVE-2025-24673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T18:45:15Z

Weaknesses