Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Easy Form easy-form allows Reflected XSS.This issue affects Easy Form: from n/a through <= 2.6.9.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw stems from an improper neutralization of user input during web page rendering, exposing the Easy Form plugin to reflected cross‑site scripting. A malicious actor can inject crafted payloads into form or URL parameters that the plugin echoes back to the browser, enabling the execution of arbitrary JavaScript in the victim’s context. Such execution may steal session cookies, manipulate page content, or redirect users to phishing sites, thereby compromising confidentiality, integrity, or availability of user data entrusted to WordPress sites.

Affected Systems

The vulnerability is present in the Easy Form plugin for WordPress distributed by Ays Pro, from the earliest unreleased revision through version 2.6.9 inclusive. Users of any WordPress site that have installed or activated this plugin in those versions are directly impacted.

Risk and Exploitability

The CVSS score of 7.1 places the flaw in the high‑severity range, and the EPSS score of <1% indicates a very low likelihood of widespread exploitation as of the data snapshot. The flaw is not listed in the CISA KEV catalogue, suggesting no confirmed exploitation at this time. Attackers would likely construct a malicious link or form submission with injected script, and a victim who clicks or submits the crafted input would trigger execution in the victim’s browser. The impact is confined to the scope of the affected user’s session context.

Generated by OpenCVE AI on May 2, 2026 at 01:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Easy Form plugin to the latest available version, which removes the reflected XSS flaw.
  • If an immediate update is not feasible, disable the risky form fields or remove the plugin from production environments until a patched version is available.
  • Implement application‑level input validation or a web‑application firewall rule that blocks unexpected script payloads in form submissions and URL parameters.

Generated by OpenCVE AI on May 2, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11619 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Easy Form by AYS allows Reflected XSS. This issue affects Easy Form by AYS: from n/a through 2.6.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Easy Form by AYS allows Reflected XSS. This issue affects Easy Form by AYS: from n/a through 2.6.9. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Easy Form easy-form allows Reflected XSS.This issue affects Easy Form: from n/a through <= 2.6.9.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Easy Form by AYS allows Reflected XSS. This issue affects Easy Form by AYS: from n/a through 2.6.9.
Title WordPress Easy Form by AYS Plugin <= 2.6.9 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:47.300Z

Reserved: 2025-02-21T16:45:19.169Z

Link: CVE-2025-27285

cve-icon Vulnrichment

Updated: 2025-04-17T17:44:03.279Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:35.143

Modified: 2026-06-17T09:03:20.257

Link: CVE-2025-27285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T02:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')