Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OwnerRez OwnerRez API ownerrez allows Stored XSS.This issue affects OwnerRez API: from n/a through <= 1.2.1.
Published: 2025-07-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The OwnerRez API plugin contains an Improper Neutralization of Input During Web Page Generation (Cross‑Site Scripting) flaw that allows attackers to inject malicious scripts into stored content. According to the description, this leads to a stored XSS vulnerability affecting any user interface that renders the compromised input. The resulting compromise can enable session hijacking, defacement, or transmission of further payloads, mapping to CWE‑79.

Affected Systems

The weakness is present in the OwnerRez API plugin for all releases from the earliest known version up to and including 1.2.1. No higher version information is supplied, so any site running 1.2.1 or earlier is susceptible. The product is the OwnerRez API plugin integrated into WordPress installations.

Risk and Exploitability

The CVSS base score is 6.5, indicating moderate severity, while the EPSS score is less than 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker could exploit the flaw by inserting malicious payloads through any input field that the plugin processes and persists, then coercing site visitors to execute the script when the content is displayed. Since the plugin is a WordPress component, input is typically available to authenticated or optionally unauthenticated users, but the stored nature implies the attack vector is likely from an authenticated operator or contributor who uploads or edits content on the site. No public exploit code is documented.

Generated by OpenCVE AI on May 1, 2026 at 07:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the OwnerRez API plugin to the latest release that fixes the XSS issue.
  • If an immediate upgrade is not possible, temporarily disable the plugin until a patch can be applied.
  • Conduct a thorough audit of all stored content managed by the plugin and remove or sanitize any embedded scripts.
  • Deploy a Web Application Firewall with XSS filtering and enforce a strong Content Security Policy to block injection attempts.

Generated by OpenCVE AI on May 1, 2026 at 07:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19950 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OwnerRez OwnerRez allows Stored XSS. This issue affects OwnerRez: from n/a through 1.2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OwnerRez OwnerRez allows Stored XSS. This issue affects OwnerRez: from n/a through 1.2.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OwnerRez OwnerRez API ownerrez allows Stored XSS.This issue affects OwnerRez API: from n/a through <= 1.2.1.
Title WordPress OwnerRez plugin <= 1.2.1 - Cross Site Scripting (XSS) Vulnerability WordPress OwnerRez API plugin <= 1.2.1 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 09 Jul 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Jul 2025 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OwnerRez OwnerRez allows Stored XSS. This issue affects OwnerRez: from n/a through 1.2.1.
Title WordPress OwnerRez plugin <= 1.2.1 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:51.657Z

Reserved: 2025-03-11T08:10:19.509Z

Link: CVE-2025-28957

cve-icon Vulnrichment

Updated: 2025-07-07T19:45:56.480Z

cve-icon NVD

Status : Deferred

Published: 2025-07-04T09:15:30.007

Modified: 2026-06-17T09:04:57.277

Link: CVE-2025-28957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T07:15:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')