Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicola Mustone WP Discord Post wp-discord-post allows Reflected XSS.This issue affects WP Discord Post: from n/a through <= 2.1.0.
Published: 2025-03-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the WP Discord Post plugin is an improper neutralization of input during web page generation, classified as a reflected XSS (CWE‑79). When an attacker supplies crafted input that the plugin reflects back into a page, arbitrary JavaScript can execute in the victim’s browser. An attacker can then steal credentials, hijack sessions, or redirect users to malicious sites, potentially compromising confidentiality, integrity, and availability of the site’s frontend. No privileged server access is required; the impact is limited to clients who open the affected content.

Affected Systems

The flaw affects any WordPress installation running the WP Discord Post plugin version 2.1.0 or earlier. The plugin is developed by Nicola Mustone, and the vulnerability applies across all affected releases from any previous version through 2.1.0.

Risk and Exploitability

The CVSS base score of 7.1 indicates a medium‑to‑high risk. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the flaw is not listed in the CISA KEV catalog. The likely attack vector involves a crafted URL or form submission that the plugin processes and reflects back without proper sanitization. Authentication is not required; the attack works on any page that displays the reflected data, making it a client‑side vulnerability but with potentially serious consequences if user sessions are compromised.

Generated by OpenCVE AI on May 1, 2026 at 13:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Discord Post to the latest version (any release newer than 2.1.0) as soon as it is available.
  • If an update cannot be applied immediately, edit the plugin’s code to sanitize or strip user‑supplied input that is echoed back to the page, or disable the features that accept unchecked query parameters.
  • Deploy a Web Application Firewall or a security plugin that blocks reflected XSS payloads (e.g., Wordfence, Sucuri) to provide a temporary safeguard until a patch can be installed.

Generated by OpenCVE AI on May 1, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-6642 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Discord Post allows Reflected XSS. This issue affects WP Discord Post: from n/a through 2.1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Discord Post allows Reflected XSS. This issue affects WP Discord Post: from n/a through 2.1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicola Mustone WP Discord Post wp-discord-post allows Reflected XSS.This issue affects WP Discord Post: from n/a through <= 2.1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00047}

epss

{'score': 0.00072}


Mon, 17 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 15 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Discord Post allows Reflected XSS. This issue affects WP Discord Post: from n/a through 2.1.0.
Title WordPress WP Discord Post Plugin <= 2.1.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:38.327Z

Reserved: 2025-02-12T13:58:39.276Z

Link: CVE-2025-26554

cve-icon Vulnrichment

Updated: 2025-03-17T16:13:32.212Z

cve-icon NVD

Status : Deferred

Published: 2025-03-15T22:15:13.267

Modified: 2026-04-23T15:25:47.857

Link: CVE-2025-26554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:00:15Z

Weaknesses