Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Variable Inspector variable-inspector allows Reflected XSS.This issue affects Variable Inspector: from n/a through <= 2.6.2.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input in the Bowo Variable Inspector plugin causes reflected cross‑site scripting. An attacker can embed malicious JavaScript that will run in the victim’s browser when a crafted link is visited or an input field is reflected back in a page. The vulnerability falls under CWE‑79 and can enable attackers to steal session cookies, perform phishing, or execute other client‑side attacks. The impact is confined to the context of the user’s browser and does not affect the plugin’s server‑side components directly.

Affected Systems

All installations of the Bowo Variable Inspector plugin with version 2.6.2 or earlier, including all earlier releases. The vulnerability affects WordPress sites that have the plugin active.

Risk and Exploitability

The CVSS score of 7.1 classifies the issue as high severity; however, the EPSS score of less than 1% indicates a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Because the exploit is reflected, the attack vector is typically an HTTP GET or POST request that the victim follows; it requires the victim to load the maliciously crafted link or trigger the reflected input, making it a classic human‑interaction based XSS. Based on the description, the attack vector requires a victim to load a crafted URL or input malicious payload, confirming the reliance on user interaction. This moderate exploitability, combined with high severity, warrants prompt remediation.

Generated by OpenCVE AI on May 2, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Variable Inspector plugin to a version newer than 2.6.2 to remove the input sanitization flaw (CWE‑79).
  • If the plugin is not required, uninstall or disable it entirely to eliminate the attack surface.
  • Deploy or configure a web application firewall rule to filter or block script injection attempts targeting the plugin’s query parameters (CWE‑79).

Generated by OpenCVE AI on May 2, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5612 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Variable Inspector allows Reflected XSS. This issue affects Variable Inspector: from n/a through 2.6.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Variable Inspector allows Reflected XSS. This issue affects Variable Inspector: from n/a through 2.6.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Variable Inspector variable-inspector allows Reflected XSS.This issue affects Variable Inspector: from n/a through <= 2.6.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Variable Inspector allows Reflected XSS. This issue affects Variable Inspector: from n/a through 2.6.2.
Title WordPress Variable Inspector plugin <= 2.6.2 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:43.897Z

Reserved: 2025-02-17T11:50:52.141Z

Link: CVE-2025-26914

cve-icon Vulnrichment

Updated: 2025-03-03T14:18:46.686Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:56.500

Modified: 2026-06-17T09:02:35.770

Link: CVE-2025-26914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:45:33Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')