Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelpro Cookies Pro cookies-pro allows Reflected XSS.This issue affects Cookies Pro: from n/a through <= 1.0.
Published: 2025-03-26
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Cookies Pro plugin for WordPress fails to neutralize input that it subsequently displays in web pages, resulting in a reflected cross‑site scripting flaw. A malicious actor can embed JavaScript or other executable payloads into a value that the plugin echoes back to the browser. Upon visiting the affected page, the payload executes in the victim’s context, allowing the attacker to steal session data, bypass secondary authentication, or perform further phishing attacks. This is a classic example of CWE‑79 because user supplied data is not properly filtered before rendering.

Affected Systems

Any WordPress site that has the Pixelpro Cookies Pro plugin version 1.0 or earlier is vulnerable. No lower bound on the version was provided, so installations from the earliest release up to and including 1.0 may all be affected. Operators should verify the presence of the plugin and its version before applying remediation.

Risk and Exploitability

The CVSS score of 7.1 classifies this flaw as medium‑high severity. The EPSS score of less than 1% indicates a very low likelihood that an attacker will exploit this vulnerability at present, and the vulnerability is not catalogued in the CISA KEV list. The weakness can be triggered via a web request that includes the malicious input, so an attacker only needs to lure a victim to the crafted URL or embed the payload in a link that the victim clicks. Because the flaw is reflected, it affects any user who visits the malformed page, but it does not persist beyond the dedicated request. Thus the risk to a site is significant primarily for sites with vulnerable visitors and no strong orthogonal controls.

Generated by OpenCVE AI on May 2, 2026 at 08:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Cookies Pro to a version that implements proper input sanitization or apply the official vendor patch if available.
  • If no patch exists, deactivate the plugin until the issue is fixed to eliminate the attack surface.
  • As an interim measure, block or sanitize any input containing script tags or other executable content, and enforce a same‑site cookie policy to reduce the impact of any stolen session data.

Generated by OpenCVE AI on May 2, 2026 at 08:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8173 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Cookies Pro allows Reflected XSS. This issue affects Cookies Pro: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Cookies Pro allows Reflected XSS. This issue affects Cookies Pro: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelpro Cookies Pro cookies-pro allows Reflected XSS.This issue affects Cookies Pro: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 26 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Cookies Pro allows Reflected XSS. This issue affects Cookies Pro: from n/a through 1.0.
Title WordPress Cookies Pro plugin <= 1.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:37.963Z

Reserved: 2025-02-12T13:58:25.801Z

Link: CVE-2025-26546

cve-icon Vulnrichment

Updated: 2025-03-26T15:25:07.622Z

cve-icon NVD

Status : Deferred

Published: 2025-03-26T15:16:10.050

Modified: 2026-04-23T15:25:46.883

Link: CVE-2025-26546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:00:11Z

Weaknesses