Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appten Image Rotator appten-image-rotator allows Reflected XSS.This issue affects Image Rotator: from n/a through <= 2.0.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation allows an attacker to inject arbitrary JavaScript into pages served by the Image Rotator plugin in WordPress. This reflected XSS flaw can be exploited to steal victims' cookies, hijack sessions, or deface a site. The weakness is identified as CWE-79.

Affected Systems

The vulnerability affects the appten Image Rotator WordPress plugin, versions up to and including 2.0. WordPress sites that keep this plugin installed and have not applied the latest update are potentially exposed.

Risk and Exploitability

The CVSS score of 7.1 reflects a Medium to High severity, while the EPSS score of <1% indicates a low likelihood of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS facilitated by malicious query parameters or user input that reaches the plugin without proper sanitization.

Generated by OpenCVE AI on May 1, 2026 at 14:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Image Rotator plugin to the latest available version (≥ 2.1) to eliminate the reflected XSS flaw.
  • If no patch is available, remove or disable the Image Rotator plugin until an update is released.
  • Implement a strict Content Security Policy that disallows inline scripts on the site to reduce the impact of any remaining XSS vectors.
  • Review site URLs for parameter usage and ensure all user-generated content is properly encoded before rendering.

Generated by OpenCVE AI on May 1, 2026 at 14:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5655 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appten Image Rotator allows Reflected XSS. This issue affects Image Rotator: from n/a through 2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appten Image Rotator allows Reflected XSS. This issue affects Image Rotator: from n/a through 2.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appten Image Rotator appten-image-rotator allows Reflected XSS.This issue affects Image Rotator: from n/a through <= 2.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appten Image Rotator allows Reflected XSS. This issue affects Image Rotator: from n/a through 2.0.
Title WordPress Image Rotator plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:35.156Z

Reserved: 2025-02-03T13:34:11.344Z

Link: CVE-2025-25089

cve-icon Vulnrichment

Updated: 2025-03-03T16:00:24.707Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:50.053

Modified: 2026-04-23T15:25:33.313

Link: CVE-2025-25089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:45:16Z

Weaknesses