Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in newbiesup WP Frontend Submit wp-frontend-submit allows Reflected XSS.This issue affects WP Frontend Submit: from n/a through <= 1.1.0.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The issue is an instance of Improper Neutralization of Input During Web Page Generation, commonly known as Cross‑Site Scripting. Attackers can embed malicious JavaScript in user‑supplied data that the plugin echoes back to the browser. Because the injected script runs in the victim’s browser context, an attacker could steal session cookies, deface the front‑end, or redirect users to malicious sites, thereby compromising confidentiality and integrity of the website’s front‑end.

Affected Systems

The vulnerability affects the WP Frontend Submit plugin from newbiesup, specifically every release through version 1.1.0. WordPress sites that have not upgraded beyond this version and still use the plugin for front‑end form submission are potentially exposed.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests exploitation attempts are expected to be rare. The vulnerability is not listed in the CISA KEV catalog. Attackers must be able to supply a malicious payload in a request processed by the plugin, so the attack requires user interaction, such as clicking a crafted link or submitting a malicious form.

Generated by OpenCVE AI on May 2, 2026 at 03:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Frontend Submit to any release newer than 1.1.0.
  • If an immediate update is not possible, temporarily deactivate the plugin or disable its front‑end form features until the update is applied.
  • Apply site‑wide input sanitization—wrap form input handling in a PHP filter that encodes output—to mitigate the risk until the plugin is patched.

Generated by OpenCVE AI on May 2, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5634 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Frontend Submit allows Cross-Site Scripting (XSS). This issue affects WP Frontend Submit: from n/a through 1.1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Frontend Submit allows Cross-Site Scripting (XSS). This issue affects WP Frontend Submit: from n/a through 1.1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in newbiesup WP Frontend Submit wp-frontend-submit allows Reflected XSS.This issue affects WP Frontend Submit: from n/a through <= 1.1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Frontend Submit allows Cross-Site Scripting (XSS). This issue affects WP Frontend Submit: from n/a through 1.1.0.
Title WordPress WP Frontend Submit Plugin <= 1.1.0 - Reflected Cross-Site Scripting vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:36.446Z

Reserved: 2025-02-03T13:34:59.204Z

Link: CVE-2025-25133

cve-icon Vulnrichment

Updated: 2025-03-03T15:48:24.119Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:53.060

Modified: 2026-06-17T09:00:21.167

Link: CVE-2025-25133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')