Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Snow Storm snow-storm allows Reflected XSS.This issue affects Snow Storm: from n/a through <= 1.4.6.
Published: 2025-04-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation allows a reflected cross‑site scripting vulnerability in the Tribulant Software Snow Storm plugin. The flaw permits an attacker to inject arbitrary JavaScript into pages rendered to other users, compromising the confidentiality and integrity of their web browsing session and enabling execution of malicious code on victims’ browsers.

Affected Systems

The vulnerability affects the Snow Storm plugin for WordPress from the initial release through version 1.4.6. Any WordPress installation using the plugin in these versions is susceptible.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score is less than 1%, suggesting a low probability of mass exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS scenario in which an attacker supplies specially crafted input—such as a query string or form field value—that the plugin fails to sanitize and subsequently renders in the page returned to the victim. An attacker who succeeds can hijack user sessions, deface content, or spread malware.

Generated by OpenCVE AI on May 1, 2026 at 01:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Snow Storm plugin to a version newer than 1.4.6.
  • Disable or remove the plugin from the WordPress site until a patched version is available.
  • Ensure that any user input is properly escaped or removed before it is rendered in the webpage.

Generated by OpenCVE AI on May 1, 2026 at 01:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14795 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Snow Storm allows Reflected XSS. This issue affects Snow Storm: from n/a through 1.4.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Snow Storm allows Reflected XSS. This issue affects Snow Storm: from n/a through 1.4.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Snow Storm snow-storm allows Reflected XSS.This issue affects Snow Storm: from n/a through <= 1.4.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 03 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Apr 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Snow Storm allows Reflected XSS. This issue affects Snow Storm: from n/a through 1.4.6.
Title WordPress Snow Storm plugin <= 1.4.6 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:58.902Z

Reserved: 2025-03-26T09:21:01.288Z

Link: CVE-2025-30858

cve-icon Vulnrichment

Updated: 2025-04-03T14:59:22.700Z

cve-icon NVD

Status : Deferred

Published: 2025-04-03T14:15:33.973

Modified: 2026-04-23T15:27:12.343

Link: CVE-2025-30858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T01:15:05Z

Weaknesses