Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata wptemplata allows Reflected XSS.This issue affects WP Templata: from n/a through <= 1.0.7.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a reflected cross‑site scripting flaw caused by improper input neutralization in the HasThemes WP Templata plugin. A malicious actor can craft a URL that injects JavaScript into the page, causing it to execute in the victim's browser. The effect is the execution of arbitrary client‑side code, which can lead to session hijacking, defacement, or data theft from the user’s session. The CVSS score of 7.1 indicates a high severity impact, while the EPSS score of less than 1 % implies a low likelihood of exploitation in the wild at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog.

Affected Systems

The flaw affects the WordPress WP Templata plugin developed by HasThemes. All installations running version 1.0.7 or earlier are vulnerable. No specific sub‑versions were enumerated beyond this upper bound.

Risk and Exploitability

Given the high CVSS, the risk of damage is significant if an attacker can reach the vulnerable endpoint. The most plausible attack path is via a reflected parameter in a URL or form field, as indicated by the description; this is inferred because the vulnerability is described as reflected XSS. No requirement for authentication is stated, suggesting the exploit could be performed by a remote unauthenticated user. The low EPSS suggests that, although the technical risk is high, the chance of automated exploitation remains limited at present. Monitoring and patching remain advisable.

Generated by OpenCVE AI on May 1, 2026 at 14:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to WP Templata 1.0.8 or newer, which removes the vulnerable code.
  • If an immediate upgrade is not possible, remove or deactivate the plugin until a patched version is available.
  • Apply input sanitization on the relevant fields by using WordPress functions such as wp_kses() or enforce a strong Content Security Policy to mitigate any remaining reflected script injections.

Generated by OpenCVE AI on May 1, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5620 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata allows Reflected XSS. This issue affects WP Templata: from n/a through 1.0.7.
History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata allows Reflected XSS. This issue affects WP Templata: from n/a through 1.0.7. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata wptemplata allows Reflected XSS.This issue affects WP Templata: from n/a through <= 1.0.7.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 20 Mar 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Hasthemes
Hasthemes wp Templata
CPEs cpe:2.3:a:hasthemes:wp_templata:*:*:*:*:*:wordpress:*:*
Vendors & Products Hasthemes
Hasthemes wp Templata

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata allows Reflected XSS. This issue affects WP Templata: from n/a through 1.0.7.
Title WordPress WP Templata plugin <= 1.0.7 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Hasthemes Wp Templata
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:54.708Z

Reserved: 2025-02-17T11:51:01.643Z

Link: CVE-2025-26917

cve-icon Vulnrichment

Updated: 2025-03-03T15:14:06.504Z

cve-icon NVD

Status : Modified

Published: 2025-03-03T14:15:56.640

Modified: 2026-04-29T10:16:42.757

Link: CVE-2025-26917

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:15:20Z

Weaknesses