Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Vice Versa vice-versa allows Reflected XSS.This issue affects Vice Versa: from n/a through <= 2.2.3.
Published: 2025-04-10
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Vice Versa WordPress plugin allows attackers to inject malicious scripts via reflected input in the web page rendering process. This improper neutralization can lead to user‑agent execution of arbitrary scripts, compromising confidentiality, integrity, and availability of website content.

Affected Systems

WordPress sites running Hugh Mungus Vice Versa plugin version 2.2.3 or earlier are vulnerable. The issue applies to all installations using those pre‑2.2.4 releases regardless of other plugins or themes.

Risk and Exploitability

The configurable CVSS score of 7.1 indicates a high impact. The EPSS score is less than 1%, suggesting a low prevalence of imminent exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this weakness by manipulating reflected request parameters that the plugin includes unfiltered in generated HTML, typically via crafted URLs or search bar entries. A successful exploit would enable the execution of injected scripts in the context of the victim’s browser.

Generated by OpenCVE AI on May 1, 2026 at 10:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Vice Versa plugin to version 2.2.4 or newer, which removes the XSS flaw.
  • If an update is not immediately possible, temporarily disable or remove the plugin from the site until a patch is applied.
  • After applying the patch, verify that no reflected input remains unescaped and monitor site logs for attempts to inject malicious scripts.

Generated by OpenCVE AI on May 1, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10678 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Vice Versa allows Reflected XSS.This issue affects Vice Versa: from n/a through 2.2.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Vice Versa allows Reflected XSS.This issue affects Vice Versa: from n/a through 2.2.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Vice Versa vice-versa allows Reflected XSS.This issue affects Vice Versa: from n/a through <= 2.2.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 10 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 10:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Vice Versa allows Reflected XSS.This issue affects Vice Versa: from n/a through 2.2.3.
Title WordPress Vice Versa plugin <= 2.2.3 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:48.879Z

Reserved: 2025-02-21T16:46:02.627Z

Link: CVE-2025-27350

cve-icon Vulnrichment

Updated: 2025-04-10T13:27:53.797Z

cve-icon NVD

Status : Deferred

Published: 2025-04-10T11:15:45.660

Modified: 2026-04-23T15:26:25.367

Link: CVE-2025-27350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:45:05Z

Weaknesses