Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atikul AI Preloader ai-preloader allows Stored XSS.This issue affects AI Preloader: from n/a through <= 1.0.2.
Published: 2025-03-24
Score: 5.9 Medium
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to store malicious scripts in the WordPress AI Preloader plugin, which are later rendered unsanitized into web pages. This leads to Stored Cross-site Scripting, enabling arbitrary JavaScript execution in the browsers of any user who views the affected content. The impact is primarily confidentiality and integrity of the user session, potentially allowing credential theft, session hijacking, or defacement of content. The weakness is a classic input validation flaw (CWE-79).

Affected Systems

The affected product is the Atikul AI Preloader WordPress plugin, version 1.0.2 and older. Users running this plugin on any website are at risk.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation attempts have not been widely observed, yet the fact that the vulnerability is stored XSS means that any content an attacker can persist in the plugin (such as widget settings or custom scripts) will be executed for all visitors. Because the issue is not listed in CISA’s Known Exploited Vulnerabilities catalog, no mass exploit data is available, but the attack vector is web‑based and could be executed by an attacker who gains access to the plugin’s configuration or by any visitor to a site where malicious content has been stored by another compromised user. The risk to an organization depends on how many users are allowed to input content through the plugin and whether that data is displayed on public‑facing pages. Overall, while the likelihood of exploitation is low, the potential impact makes remediation important.

Generated by OpenCVE AI on May 1, 2026 at 04:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AI Preloader plugin to the latest version (1.0.3 or newer).
  • If an upgrade is not possible immediately, disable the plugin to prevent any malicious script execution.
  • Sanitize and cleanse any custom content stored via the plugin, removing embedded scripts or HTML that could be executed in the browser.

Generated by OpenCVE AI on May 1, 2026 at 04:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7956 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atikul AI Preloader allows Stored XSS. This issue affects AI Preloader: from n/a through 1.0.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atikul AI Preloader allows Stored XSS. This issue affects AI Preloader: from n/a through 1.0.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atikul AI Preloader ai-preloader allows Stored XSS.This issue affects AI Preloader: from n/a through <= 1.0.2.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Mon, 24 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atikul AI Preloader allows Stored XSS. This issue affects AI Preloader: from n/a through 1.0.2.
Title WordPress AI Preloader plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:53.225Z

Reserved: 2025-03-24T12:59:40.514Z

Link: CVE-2025-30530

cve-icon Vulnrichment

Updated: 2025-03-24T14:51:17.949Z

cve-icon NVD

Status : Deferred

Published: 2025-03-24T14:15:21.543

Modified: 2026-04-23T15:26:48.463

Link: CVE-2025-30530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:45:08Z

Weaknesses