Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badrHan Naver Syndication V2 badr-naver-syndication allows Stored XSS.This issue affects Naver Syndication V2: from n/a through <= 0.8.3.
Published: 2025-02-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Naver Syndication V2 plugin allows attackers to inject malicious script that is stored in the plugin’s data store. Existing users with write access can submit input that is not properly neutralized, leading to a stored Cross‑Site Scripting flaw that can be triggered when a page is rendered. The advisory notes that the vulnerability can be exploited through a CSRF‑enabled pathway, meaning an attacker could trick a legitimate user into submitting malicious payloads while authenticated.

Affected Systems

WordPress sites that have installed the Naver Syndication V2 plugin from badrHan, with versions ranging from the earliest released up through 0.8.3. Any site that uses this plugin is potentially vulnerable, regardless of the site’s overall WordPress version.

Risk and Exploitability

The CVSS score of 7.1 places this vulnerability in the high‑severity range, indicating significant impact should it be exploited. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at present, yet the possibility remains, especially in environments where the plugin is highly exposed or runs with elevated privileges. The vulnerability is not currently listed in CISA’s KEV catalog, but the stored XSS payload could be used to deface pages, steal session cookies, or deliver malware to site visitors. Exploitation would typically require a user with sufficient privileges to submit form data, combined with a CSRF vector to bypass CSRF tokens or session checks, after which the script would execute in the context of any visitor who views the affected page.

Generated by OpenCVE AI on May 1, 2026 at 16:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Naver Syndication V2 plugin to the latest version (0.8.4 or newer) to remove the flaw.
  • If an update is not available or feasible, uninstall or disable the plugin to eliminate the vulnerability surface.
  • Configure a content security policy that restricts inline scripting and blocks execution of script tags inserted in user data.
  • Apply a web‑application firewall rule that sanitizes or rejects input containing JavaScript code for the plugin’s endpoints.
  • Regularly review plugin and site logs to detect any unexpected script injections or changes to page content.

Generated by OpenCVE AI on May 1, 2026 at 16:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4219 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badrHan Naver Syndication V2 allows Stored XSS. This issue affects Naver Syndication V2: from n/a through 0.8.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badrHan Naver Syndication V2 allows Stored XSS. This issue affects Naver Syndication V2: from n/a through 0.8.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badrHan Naver Syndication V2 badr-naver-syndication allows Stored XSS.This issue affects Naver Syndication V2: from n/a through <= 0.8.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00032}

epss

{'score': 0.00035}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00072}

epss

{'score': 0.00032}


Tue, 18 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badrHan Naver Syndication V2 allows Stored XSS. This issue affects Naver Syndication V2: from n/a through 0.8.3.
Title WordPress Naver Syndication V2 plugin <= 0.8.3 - CSRF to Stored Cross-Site Scripting vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:38.192Z

Reserved: 2025-02-12T13:58:25.802Z

Link: CVE-2025-26552

cve-icon Vulnrichment

Updated: 2025-02-13T14:33:45.531Z

cve-icon NVD

Status : Deferred

Published: 2025-02-13T14:16:21.787

Modified: 2026-04-23T15:25:47.653

Link: CVE-2025-26552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T17:00:11Z

Weaknesses