Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yuichiro ABE Meta Accelerator meta-accelerator allows Reflected XSS.This issue affects Meta Accelerator: from n/a through <= 1.0.4.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of input during web page generation, allowing an attacker to inject malicious script into a page that is then reflected back to the victim. This reflected XSS can be triggered by sending a crafted URL to a vulnerable user, enabling theft of session cookies, defacement, or execution of malicious code in the user’s browser. The weakness is marked as CWE-79 and poses a moderate confidentiality and integrity risk to visitors of the affected WordPress site.

Affected Systems

The issue affects the WordPress plugin Meta Accelerator developed by Yuichiro ABE. All releases from the initial public version up to and including version 1.0.4 are vulnerable. Site owners running any of these plugin versions should consider updating or removing the plugin.

Risk and Exploitability

With a CVSS score of 7.1, the vulnerability is considered high enough to warrant attention, yet its EPSS score of less than 1 percent indicates a low probability of widespread exploitation at present. Because the flaw is triggered via a reflected XSS vector in the browser, any user who follows a malicious link on a page served by the site could be affected. The vulnerability is not yet listed in the CISA KEV catalog, and there are no publicly documented exploits, so immediate patching remains the safest course.

Generated by OpenCVE AI on May 1, 2026 at 14:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Meta Accelerator to a version newer than 1.0.4 or to the latest patched release.
  • If an update is not immediately available, delete or deactivate the plugin until a patch is deployed.
  • Implement a Content Security Policy (CSP) that restricts script execution and mitigates XSS impact.

Generated by OpenCVE AI on May 1, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5628 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Meta Accelerator allows Reflected XSS. This issue affects Meta Accelerator: from n/a through 1.0.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Meta Accelerator allows Reflected XSS. This issue affects Meta Accelerator: from n/a through 1.0.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yuichiro ABE Meta Accelerator meta-accelerator allows Reflected XSS.This issue affects Meta Accelerator: from n/a through <= 1.0.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Meta Accelerator allows Reflected XSS. This issue affects Meta Accelerator: from n/a through 1.0.4.
Title WordPress Meta Accelerator plugin <= 1.0.4 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:37.419Z

Reserved: 2025-02-03T13:35:31.279Z

Link: CVE-2025-25164

cve-icon Vulnrichment

Updated: 2025-03-03T15:59:27.383Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:54.190

Modified: 2026-04-23T15:25:43.940

Link: CVE-2025-25164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:30:06Z

Weaknesses