Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama quotes-llama allows Reflected XSS.This issue affects Quotes llama: from n/a through <= 3.0.1.
Published: 2025-02-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability occurs in the WordPress Quotes llama plugin when user input is incorporated into web pages without proper neutralization, allowing an attacker to inject malicious script that is executed in a visitor's browser. An attacker could hijack user sessions, alter page content, or redirect users to malicious sites. The flaw is classified as a CWE‑79 XSS weakness, which directly exposes the confidentiality and integrity of users interacting with the affected site.

Affected Systems

The affected product is the Quotes llama plugin developed by oooorgle. Versions from the initial release through 3.0.1 are impacted; no higher or isolated patch version is listed in the input data.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate risk, and the EPSS score of less than 1% shows a very low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to submit a quote or otherwise feed unsanitized content to the plugin—such as an admin, contributor, or a compromised account. Once injected, the script runs within the context of the site’s front‑end, allowing client‑side attack techniques. While the risk of successful exploitation is moderate, the impact on users’ browsers can be significant, so applying the vendor‑supplied fix or disabling the vulnerable component remains the best mitigation.

Generated by OpenCVE AI on May 2, 2026 at 04:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Quotes llama plugin to version 3.0.2 or later
  • If the plugin is not required, deactivate and remove it to eliminate the vulnerability
  • Implement a Content Security Policy or deploy a web application firewall to block malicious scripts and mitigate XSS while the plugin issue remains unresolved

Generated by OpenCVE AI on May 2, 2026 at 04:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4342 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama allows Reflected XSS. This issue affects Quotes llama: from n/a through 3.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama allows Reflected XSS. This issue affects Quotes llama: from n/a through 3.0.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama quotes-llama allows Reflected XSS.This issue affects Quotes llama: from n/a through <= 3.0.1.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 24 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama allows Reflected XSS. This issue affects Quotes llama: from n/a through 3.0.1.
Title WordPress Quotes llama plugin <= 3.0.1 - Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:47.466Z

Reserved: 2025-02-21T16:45:34.056Z

Link: CVE-2025-27307

cve-icon Vulnrichment

Updated: 2025-02-24T16:56:29.832Z

cve-icon NVD

Status : Deferred

Published: 2025-02-24T15:15:16.653

Modified: 2026-06-17T09:03:22.403

Link: CVE-2025-27307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')