Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vivek Marakana Tabbed Login Widget tabbed-login allows Stored XSS.This issue affects Tabbed Login Widget: from n/a through <= 1.1.2.
Published: 2025-03-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Stored Cross‑Site Scripting (XSS) vulnerabilities allow an attacker to inject malicious scripts that are later served to all users who visit the affected page. In the Tabbed Login Widget plugin, malformed input is saved and rendered without sanitization, enabling attackers to capture the victim’s session cookie, deface the site, or redirect users to malicious domains. The flaw is a classic instance of CWE‑79: Improper Neutralization of Input During Web Page Generation.

Affected Systems

The affected product is the Tabbed Login Widget plugin developed by Vivek Marakana. All WordPress installations using this plugin at versions 1.1.2 or earlier are susceptible. The CNA description indicates that the vulnerability is present from the earliest release through ≤ 1.1.2.

Risk and Exploitability

The CVSS score of 6.5 denotes a moderate severity, and the EPSS score of less than 1% suggests that, at the time of assessment, exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV database, meaning there is no public evidence of active exploitation. Attackers would need to inject malicious payloads through the plugin’s input mechanisms, which can then be executed in the browsers of any visitor. Because the payload is stored, repeated exploitation is possible, and protection against XSS must be applied immediately.

Generated by OpenCVE AI on May 1, 2026 at 13:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Tabbed Login Widget to a version newer than 1.1.2 from the official WordPress plugin repository.
  • Temporarily deactivate the plugin until an update can be applied to prevent the vulnerability from being exploited.
  • Apply a Web Application Firewall rule or enforce a Content Security Policy that blocks the execution of unknown scripts originating from the login widget.

Generated by OpenCVE AI on May 1, 2026 at 13:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7878 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vivek Marakana Tabbed Login Widget allows Stored XSS. This issue affects Tabbed Login Widget: from n/a through 1.1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vivek Marakana Tabbed Login Widget allows Stored XSS. This issue affects Tabbed Login Widget: from n/a through 1.1.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vivek Marakana Tabbed Login Widget tabbed-login allows Stored XSS.This issue affects Tabbed Login Widget: from n/a through <= 1.1.2.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00046}

epss

{'score': 0.0007}


Wed, 12 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vivek Marakana Tabbed Login Widget allows Stored XSS. This issue affects Tabbed Login Widget: from n/a through 1.1.2.
Title WordPress Tabbed Login Widget plugin <= 1.1.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:50.629Z

Reserved: 2025-03-11T08:09:57.113Z

Link: CVE-2025-28929

cve-icon Vulnrichment

Updated: 2025-03-12T13:44:10.773Z

cve-icon NVD

Status : Deferred

Published: 2025-03-11T21:15:50.690

Modified: 2026-04-23T15:26:37.403

Link: CVE-2025-28929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:00:15Z

Weaknesses