Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Potphode Easy Charts easy-charts allows DOM-Based XSS.This issue affects Easy Charts: from n/a through <= 1.2.3.
Published: 2025-02-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Easy Charts plugin for WordPress contains a DOM‐based cross‑site scripting flaw that allows an attacker to inject malicious JavaScript into the rendered page. By providing crafted data that is not properly neutralized, an attacker can execute code in the victim’s browser session, potentially stealing session cookies, hijacking accounts, or modifying page content. This type of vulnerability is classified as CWE‑79 and can be exploited without any privileged access, relying solely on user input that reaches the front‑end rendering process.

Affected Systems

WordPress installations that use the Easy Charts plugin developed by Kiran Potphode. All versions of the plugin ranging from unknown earlier releases up to and including 1.2.3 are impacted. No specific WordPress core version is mentioned, so any site hosting this plugin within that version range is at risk.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate impact, with the EPSS score below 1% indicating a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply malicious input that the plugin directly renders, suggesting a typical cross‑site scripting attack path via a crafted URL or form submission. In the absence of advanced defenses, an attacker could achieve complete front‑end compromise of the affected site.

Generated by OpenCVE AI on May 2, 2026 at 04:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Easy Charts to any version newer than 1.2.3 where the XSS issue has been fixed.
  • If an update is not immediately available, disable or uninstall the plugin until the fix is released.
  • Check user role permissions and restrict chart creation or editing to trusted administrators only to reduce the chance that untrusted input is processed.

Generated by OpenCVE AI on May 2, 2026 at 04:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5430 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Potphode Easy Charts allows DOM-Based XSS. This issue affects Easy Charts: from n/a through 1.2.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Potphode Easy Charts allows DOM-Based XSS. This issue affects Easy Charts: from n/a through 1.2.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Potphode Easy Charts easy-charts allows DOM-Based XSS.This issue affects Easy Charts: from n/a through <= 1.2.3.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 25 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Potphode Easy Charts allows DOM-Based XSS. This issue affects Easy Charts: from n/a through 1.2.3.
Title WordPress Easy Charts plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:42.548Z

Reserved: 2025-02-17T11:50:29.987Z

Link: CVE-2025-26893

cve-icon Vulnrichment

Updated: 2025-02-25T15:25:24.451Z

cve-icon NVD

Status : Deferred

Published: 2025-02-25T15:15:25.390

Modified: 2026-06-17T09:02:33.693

Link: CVE-2025-26893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')