Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core allows Stored XSS. This issue affects Bridge Core: from n/a through n/a.
Published: 2025-04-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits stored cross‑site scripting in the Bridge Core plugin for WordPress. The flaw arises because user input is not properly neutralized before being rendered on web pages. An attacker can store malicious script through the plugin interface, causing that script to execute in the browsers of other visitors. This can lead to session hijacking, defacement, or phishing attacks, compromising confidentiality, integrity, and authenticity of the site.

Affected Systems

WordPress sites that use the Bridge Core plugin version 3.3.0 or earlier are affected. The plugin has no known basis that beta versions exist; any deployment under the v3.3.x major release before 3.3.1 is vulnerable. The vendor is the WordPress plugin author NotFound.

Risk and Exploitability

The CVSS score of 6.5 places the issue in the medium severity band. The EPSS score of less than 1% indicates that historically the likelihood of exploitation is low. The vulnerability is not yet listed by CISA in its KEV catalog. Attackers could exploit it by creating or editing content within the plugin, thereby injecting script that runs whenever other users view affected pages. The likely attack vector is a web interface that accepts user‑generated data, and the vulnerability requires the ability to input data that is subsequently displayed without sanitization.

Generated by OpenCVE AI on May 1, 2026 at 02:31 UTC.

Remediation

Vendor Solution

Update the WordPress Bridge Core plugin to the latest available version (at least 3.3.1).


OpenCVE Recommended Actions

  • Update the Bridge Core plugin to version 3.3.1 or later.
  • Remove any legacy plugin files that may remain in the wp-content/plugins/bridge-core directory.
  • Conduct a review of site content to ensure no stored malicious scripts remain, and consider implementing a content security policy to mitigate residual XSS risk.

Generated by OpenCVE AI on May 1, 2026 at 02:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9065 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core allows Stored XSS. This issue affects Bridge Core: from n/a through n/a.
History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core bridge-core allows Stored XSS.This issue affects Bridge Core: from n/a through < 3.3.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core allows Stored XSS. This issue affects Bridge Core: from n/a through n/a.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core allows Stored XSS. This issue affects Bridge Core: from n/a through n/a. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core bridge-core allows Stored XSS.This issue affects Bridge Core: from n/a through < 3.3.1.
References

Tue, 01 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 05:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core allows Stored XSS. This issue affects Bridge Core: from n/a through n/a.
Title WordPress Bridge Core plugin < 3.3.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:06.089Z

Reserved: 2025-03-28T10:59:52.730Z

Link: CVE-2025-31409

cve-icon Vulnrichment

Updated: 2025-04-01T15:08:49.669Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T06:15:56.730

Modified: 2026-04-28T19:31:01.783

Link: CVE-2025-31409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')