Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alphasis Related Posts via Categories related-posts-via-categories allows Stored XSS.This issue affects Related Posts via Categories: from n/a through <= 2.1.2.
Published: 2025-03-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The alphasis Related Posts via Categories plugin contains a stored cross‑site scripting flaw that is triggered through a CSRF‑enabled request. Unfiltered user input can be submitted and stored in the database; when the page is subsequently rendered the payload executes in the context of any visitor to the site. As a result, attackers could steal credentials, deface content, or perform further attacks against users of the affected WordPress site. The weakness is reflected by CWE‑79.

Affected Systems

Any WordPress installation that has the alphasis Related Posts via Categories plugin version 2.1.2 or earlier installed is vulnerable. Sites that include this plugin—regardless of any other security controls—are at risk until the plugin is updated or removed.

Risk and Exploitability

The CVSS score of 7.1 classifies this vulnerability as high severity, but the EPSS score of less than 1 % indicates that active exploitation is currently rare. The flaw is not listed in the CISA KEV catalog. Exploitation requires a user session with privileges sufficient to submit a post or modify plugin settings; an attacker can trigger the issue via a malicious link, form, or embedded HTTP request. The attack path relies on a legitimate authenticated request that is crafted to send malicious payload data.

Generated by OpenCVE AI on May 2, 2026 at 03:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Related Posts via Categories plugin to any version newer than 2.1.2 once it becomes available.
  • If an upgrade is not immediately possible, remove or deactivate the plugin to eliminate the attack surface.
  • Restrict administrative and post‑submission privileges to trusted users, and enforce CSRF protections on all state‑changing requests to prevent malicious data from being stored.

Generated by OpenCVE AI on May 2, 2026 at 03:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7928 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alphasis Related Posts via Categories allows Stored XSS. This issue affects Related Posts via Categories: from n/a through 2.1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alphasis Related Posts via Categories allows Stored XSS. This issue affects Related Posts via Categories: from n/a through 2.1.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alphasis Related Posts via Categories related-posts-via-categories allows Stored XSS.This issue affects Related Posts via Categories: from n/a through <= 2.1.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 25 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alphasis Related Posts via Categories allows Stored XSS. This issue affects Related Posts via Categories: from n/a through 2.1.2.
Title WordPress Related Posts via Categories plugin <= 2.1.2 - CSRF to Stored XSS vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:55.068Z

Reserved: 2025-03-24T13:00:39.013Z

Link: CVE-2025-30602

cve-icon Vulnrichment

Updated: 2025-03-25T17:45:22.794Z

cve-icon NVD

Status : Deferred

Published: 2025-03-24T14:15:32.667

Modified: 2026-04-23T15:26:57.133

Link: CVE-2025-30602

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:30:16Z

Weaknesses