Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shalomworld SW Plus shalom-world-media-gallery allows Reflected XSS.This issue affects SW Plus: from n/a through <= 2.1.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Reflected cross‑site scripting (XSS) occurs when untrusted data is reflected back to the browser without proper escaping, allowing an attacker to inject arbitrary client‑side scripts. In this case, the shalomworld SW Plus plugin fails to neutralize user input during page generation, thereby permitting attacker‑supplied payloads to execute in the victim’s browser. This weakness can lead to session hijacking, credential theft, defacement, or the delivery of other malicious content to unsuspecting users. The vulnerability is classified under CWE‑79 – Improper Neutralization of Input During Web Page Generation.

Affected Systems

Affected hosts are those running the SW Plus plugin from shalomworld, for versions up until 2.1, inclusive. The plugin is a WordPress media gallery add‑on, commonly found on sites that use shalomworld’s Media Gallery functionality. Any WordPress installation that includes SW Plus 2.1 or earlier is potentially susceptible, while releases 2.2 and later incorporate the fix described by the vendor.

Risk and Exploitability

The CVSS score of 7.1 indicates medium‑high severity. EPSS is <1%, suggesting that overall exploitation probability is low but still non‑zero. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can likely exploit it by crafting URLs or form inputs that include malicious JavaScript, which the plugin then reflects back in the page HTML. Because it is a reflected XSS, the attack requires user interaction to load the malicious page; however, on sites with open search or public comments, an attacker could embed the payload in a link and persuade visitors to click. Mitigating this risk requires applying the vendor patch or disabling the problematic functionality until it can be updated.

Generated by OpenCVE AI on May 1, 2026 at 14:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SW Plus to the latest release (v2.2 or later) to apply the vendor‑provided fix for the reflected XSS bug.
  • If upgrading is delayed, restrict access to the plugin’s front‑end output or admin interface to trusted users only, and block exposure of unescaped user data.
  • Implement server‑side input validation and output encoding for any data submitted through the plugin, e.g., use htmlspecialchars() when rendering user values.
  • Deploy a Web Application Firewall that blocks or sanitizes suspicious JavaScript payloads in query parameters and form submissions.

Generated by OpenCVE AI on May 1, 2026 at 14:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5652 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shalomworld SW Plus allows Reflected XSS. This issue affects SW Plus: from n/a through 2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shalomworld SW Plus allows Reflected XSS. This issue affects SW Plus: from n/a through 2.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shalomworld SW Plus shalom-world-media-gallery allows Reflected XSS.This issue affects SW Plus: from n/a through <= 2.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shalomworld SW Plus allows Reflected XSS. This issue affects SW Plus: from n/a through 2.1.
Title WordPress SW Plus Plugin <= 2.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:35.546Z

Reserved: 2025-02-03T13:34:30.657Z

Link: CVE-2025-25108

cve-icon Vulnrichment

Updated: 2025-03-03T16:00:07.291Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:50.767

Modified: 2026-04-23T15:25:37.243

Link: CVE-2025-25108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:45:16Z

Weaknesses