Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest wp-find-your-nearest allows Reflected XSS.This issue affects WP Find Your Nearest: from n/a through <= 0.3.1.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Find Your Nearest plugin for WordPress contains an improper neutralization of user‑supplied input during page generation, resulting in a reflected Cross‑Site Scripting (XSS) vulnerability. An attacker could embed malicious JavaScript in URLs that the plugin reflects on its settings pages, allowing execution of arbitrary code in the browser of any user who views the affected page. The impact could subsequently include theft of authentication data or execution of additional payloads, though the description does not confirm these extensions. Rather, the vulnerability provides the capability for client‑side code execution and leaves the scope to the attacker’s objective.

Affected Systems

Versions of the SocialEvolution WP Find Your Nearest plugin from the initial release through 0.3.1 are affected. Site administrators who have installed this plugin from WordPress.org or other sources may be exposed if the vulnerable version remains in use.

Risk and Exploitability

The CVSS score of 7.1 classifies the flaw as high severity. The EPSS score of less than 1% indicates that, at the time of assessment, exploitation is considered rare. The issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a malicious link that incorporates the vulnerable input; however, this is inferred rather than explicitly stated. No user authentication is required to trigger the vulnerability, meaning the attack can succeed against any user who visits the crafted URL.

Generated by OpenCVE AI on May 2, 2026 at 03:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Find Your Nearest to a version newer than 0.3.1 once an update that addresses the XSS flaw is released.
  • If a patch is not yet available, uninstall or disable the plugin to remove the vulnerable component.
  • Deploy a Content Security Policy that disallows inline scripts, or configure a Web Application Firewall to detect and block reflected XSS payloads.

Generated by OpenCVE AI on May 2, 2026 at 03:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5644 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Find Your Nearest allows Reflected XSS. This issue affects WP Find Your Nearest: from n/a through 0.3.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Find Your Nearest allows Reflected XSS. This issue affects WP Find Your Nearest: from n/a through 0.3.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest wp-find-your-nearest allows Reflected XSS.This issue affects WP Find Your Nearest: from n/a through <= 0.3.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Find Your Nearest allows Reflected XSS. This issue affects WP Find Your Nearest: from n/a through 0.3.1.
Title WordPress WP Find Your Nearest Plugin <= 0.3.1 - CSRF to Settings Change vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:37.052Z

Reserved: 2025-02-03T13:35:31.279Z

Link: CVE-2025-25161

cve-icon Vulnrichment

Updated: 2025-03-03T15:59:30.469Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:53.900

Modified: 2026-04-23T15:25:43.503

Link: CVE-2025-25161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:00:13Z

Weaknesses