Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphems List Urls list-urls allows Reflected XSS.This issue affects List Urls: from n/a through <= 0.2.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The List Urls WordPress plugin (up to version 0.2) contains an improper neutralization of input during web page generation vulnerability that allows reflected XSS. An attacker who can supply crafted request parameters can cause the plugin to echo those parameters without proper escaping, leading to arbitrary script execution in a victim’s browser. This could enable credential theft, session hijacking, or malicious site defacement. The vulnerability is a client‑side XSS flaw (CWE‑79).

Affected Systems

WordPress sites running the graphems List Urls plugin with versions 0.2 or earlier. The vulnerability affects all releases from the earliest available version up to and including 0.2.

Risk and Exploitability

The CVSS score of 7.1 rates the flaw as high severity, while the EPSS score of <1% indicates a low probability of exploitation at present. The flaw is not listed in CISA’s KEV catalog. Exploitation likely requires the attacker to convince a user to visit a crafted URL or submit a malicious form, enabling the reflected payload to execute in the user’s browser. Given the client‑side nature of the attack, no local privileges are necessary, and the impact depends on the victim’s trust level. With the low EPSS and absence from KEV, the risk remains moderate, but the high CVSS warrants an immediate patch.

Generated by OpenCVE AI on May 1, 2026 at 09:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the List Urls plugin to the latest release that fixes the reflected XSS flaw.
  • If an update is unavailable, deactivate or uninstall the plugin until a patched version is released.
  • Configure a Content Security Policy that disallows inline scripts and limits script origins to reduce the impact of any residual XSS vector.
  • Deploy a web application firewall or security plugin that blocks reflected XSS payloads and validates all input parameters.

Generated by OpenCVE AI on May 1, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11640 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphems List Urls allows Reflected XSS. This issue affects List Urls: from n/a through 0.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphems List Urls allows Reflected XSS. This issue affects List Urls: from n/a through 0.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphems List Urls list-urls allows Reflected XSS.This issue affects List Urls: from n/a through <= 0.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphems List Urls allows Reflected XSS. This issue affects List Urls: from n/a through 0.2.
Title WordPress List Urls Plugin <= 0.2 - CSRF to Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:48.762Z

Reserved: 2025-02-21T16:45:54.608Z

Link: CVE-2025-27338

cve-icon Vulnrichment

Updated: 2025-04-17T17:44:57.276Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:37.913

Modified: 2026-04-23T15:26:24.057

Link: CVE-2025-27338

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T09:45:07Z

Weaknesses