Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles easy-wp-tiles allows Stored XSS.This issue affects Easy WP Tiles: from n/a through <= 1.
Published: 2025-02-07
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input in the Easy WP Tiles plugin allows a stored XSS flaw that can execute arbitrary JavaScript when a generated page is viewed. The published description indicates that malicious code can be stored and then run within the context of any visitor’s session, potentially enabling cookie theft, session hijacking or defacement of the site. Based on the description, it is inferred that the injected script would execute with the privileges of the authenticated user who loads the affected page.

Affected Systems

WordPress installations that have the Easy WP Tiles plugin version 1 or earlier. No further version granularity is disclosed, so any site with this plugin configured at or below the stated upper bound is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.9 denotes a moderate severity vulnerability. The EPSS score of less than 1 % and the absence from the CISA KEV catalog imply a low likelihood of widespread exploitation at present. The likely attack vector is via the plugin’s content‑submission interface; an attacker with permission to create or edit content within the plugin can embed the malicious script that will subsequently be stored and delivered to all visitors. Because it is a stored XSS, no elevated privileges beyond the ability to use the plugin’s interface are required, making it relatively straightforward to deploy if authenticated access is available.

Generated by OpenCVE AI on May 2, 2026 at 04:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Easy WP Tiles to the latest version that removes the XSS flaw.
  • If an upgrade is not possible, uninstall or disable the plugin to eliminate the stored XSS vectors.
  • Implement a strong content‑security policy and enforce input sanitization on the WordPress site to mitigate similar injection attacks in the future.

Generated by OpenCVE AI on May 2, 2026 at 04:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4013 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles allows Stored XSS. This issue affects Easy WP Tiles: from n/a through 1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles allows Stored XSS. This issue affects Easy WP Tiles: from n/a through 1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles easy-wp-tiles allows Stored XSS.This issue affects Easy WP Tiles: from n/a through <= 1.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Fri, 07 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles allows Stored XSS. This issue affects Easy WP Tiles: from n/a through 1.
Title WordPress Easy WP Tiles plugin <= 1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:34.776Z

Reserved: 2025-02-03T13:34:00.630Z

Link: CVE-2025-25073

cve-icon Vulnrichment

Updated: 2025-02-07T15:42:35.426Z

cve-icon NVD

Status : Deferred

Published: 2025-02-07T10:15:12.197

Modified: 2026-04-23T15:25:31.330

Link: CVE-2025-25073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:00:12Z

Weaknesses