Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpchurchteam WP Church Center wp-church-center allows Reflected XSS.This issue affects WP Church Center: from n/a through <= 1.3.3.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected XSS flaw caused by improper sanitization of user‑supplied input before rendering on a web page. This flaw enables an attacker to inject and execute arbitrary JavaScript in the browser of any user who visits a crafted URL. An attacker could use the injected code to steal session cookies, deface the site, or redirect victims to malicious sites, compromising confidentiality and availability of the web interface.

Affected Systems

The flaw exists in the WP Church Center plugin for WordPress from the earliest release, including all versions up to and including 1.3.3. The affected product is offered by wpchurchteam and used within WordPress installations that provide church‑center functionality. No patch version is listed, so any deployment running 1.3.3 or earlier is vulnerable.

Risk and Exploitability

The CVSS base score of 7.1 indicates a medium to high severity, and the EPSS score of less than 1 % shows a low likelihood of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. An attacker would need to lure a user to a crafted link or embed the payload in a URL that the plugin accepts as part of a request; no special privileges or authentication are required. Because the flaw is reflected, the impact is limited to the end‑user’s browser but can be leveraged for phishing or credential theft.

Generated by OpenCVE AI on May 1, 2026 at 14:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Church Center plugin to a version newer than 1.3.3, or remove the plugin if an update is unavailable.
  • Ensure that any user input handled by the plugin is properly escaped or sanitized before inclusion in the HTML response to mitigate reflected XSS.
  • Block or restrict access to the plugin’s request handlers or pages that accept user parameters until the vulnerability is patched, using a firewall rule or access‑control list.

Generated by OpenCVE AI on May 1, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5630 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Church Center allows Reflected XSS. This issue affects WP Church Center: from n/a through 1.3.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Church Center allows Reflected XSS. This issue affects WP Church Center: from n/a through 1.3.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpchurchteam WP Church Center wp-church-center allows Reflected XSS.This issue affects WP Church Center: from n/a through <= 1.3.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Church Center allows Reflected XSS. This issue affects WP Church Center: from n/a through 1.3.3.
Title WordPress WP Church Center Plugin <= 1.3.3 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:37.035Z

Reserved: 2025-02-03T13:35:19.029Z

Link: CVE-2025-25157

cve-icon Vulnrichment

Updated: 2025-03-03T15:26:57.215Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:53.617

Modified: 2026-04-23T15:25:43.053

Link: CVE-2025-25157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:30:06Z

Weaknesses