Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DyadyaLesha DL Leadback dl-leadback allows Reflected XSS.This issue affects DL Leadback: from n/a through <= 1.2.1.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during web page generation allows an attacker to inject malicious script that is reflected back to the victim’s browser. The injected script runs with the victim’s privileges and can steal session cookies, deface content, hijack navigation, or perform other client‑side attacks. The vulnerability is independent of authentication; any user who visits a crafted URL can be affected. It is identified as a reflective XSS flaw on the WordPress DL Leadback plugin.

Affected Systems

The vulnerability affects the DL Leadback plugin for WordPress, developed by DyadyaLesha. All installations of the plugin from its initial release through version 1.2.1 are impacted, regardless of whether the site runs an earlier or the latest 1.2.1 build.

Risk and Exploitability

With a CVSS score of 7.1 the flaw is considered high severity, yet the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting that no large‑scale, documented exploits are currently known. The attack hinges on a maliciously crafted URL that is delivered to or clicked by a user; the victim’s browser must render the reflected payload. No elevated privileges or server‑side access are required for exploitation, but social engineering to entice the target to visit the URL is usually necessary.

Generated by OpenCVE AI on May 1, 2026 at 14:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the DL Leadback plugin to a version newer than 1.2.1, or uninstall the plugin if it is not required.
  • Apply a web‑application firewall rule that blocks or sanitizes suspicious input characters before they reach the plugin’s output stage.
  • Implement a server‑side Content Security Policy that disallows inline scripts and restricts script sources to trusted domains.

Generated by OpenCVE AI on May 1, 2026 at 14:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5618 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DL Leadback allows Reflected XSS. This issue affects DL Leadback: from n/a through 1.2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DL Leadback allows Reflected XSS. This issue affects DL Leadback: from n/a through 1.2.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DyadyaLesha DL Leadback dl-leadback allows Reflected XSS.This issue affects DL Leadback: from n/a through <= 1.2.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DL Leadback allows Reflected XSS. This issue affects DL Leadback: from n/a through 1.2.1.
Title WordPress DL Leadback Plugin <= 1.2.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:39.196Z

Reserved: 2025-02-12T13:59:03.605Z

Link: CVE-2025-26585

cve-icon Vulnrichment

Updated: 2025-03-03T15:59:15.747Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:55.470

Modified: 2026-06-17T09:02:04.057

Link: CVE-2025-26585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')