Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phantom.omaga Toggle Box toggle-box allows Stored XSS.This issue affects Toggle Box: from n/a through <= 1.6.
Published: 2025-03-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Toggle Box plugin for WordPress contains a stored cross‑site scripting flaw (CWE‑79). When a user submits content through the plugin interface, the input is stored without proper neutralization and later rendered in a page. This allows an attacker to inject arbitrary JavaScript that executes in the browsers of anyone who visits the affected page, potentially stealing session cookies, defacing content, or redirecting users.

Affected Systems

The affected product is the Toggle Box plugin from the vendor phantom.omaga. Every release from the earliest version up to and including 1.6 is vulnerable; any site that has the plugin installed and uses its toggle‑box feature is at risk. There are no more recent public versions mentioned in the advisory, so sites need to verify whether they are running a patched or newer release.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% implies a low likelihood of exploitation today, which is corroborated by the absence of this vulnerability in the CISA KEV catalog. Nonetheless, the flaw can be leveraged by anyone with the ability to add or edit toggle box content, which usually requires administrative or editor privileges on the WordPress site. Attackers could use the stored script to compromise other visitors or gain additional footholds on the site, so the risk remains meaningful in a public context.

Generated by OpenCVE AI on May 1, 2026 at 03:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Toggle Box plugin to a version newer than 1.6 or remove the plugin if an upgrade is not available.
  • Restrict the ability to add or edit toggle box content to trusted administrators only, ensuring that only authorized users can input content.
  • If an update cannot be applied immediately, disable the plugin or apply a temporary filter that sanitizes the content before it is rendered to prevent script execution.

Generated by OpenCVE AI on May 1, 2026 at 03:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8583 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phantom.omaga Toggle Box allows Stored XSS. This issue affects Toggle Box: from n/a through 1.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phantom.omaga Toggle Box allows Stored XSS. This issue affects Toggle Box: from n/a through 1.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phantom.omaga Toggle Box toggle-box allows Stored XSS.This issue affects Toggle Box: from n/a through <= 1.6.
Title WordPress Toggle Box <= 1.6 - Cross Site Scripting (XSS) Vulnerability WordPress Toggle Box plugin <= 1.6 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 12:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phantom.omaga Toggle Box allows Stored XSS. This issue affects Toggle Box: from n/a through 1.6.
Title WordPress Toggle Box <= 1.6 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:07.289Z

Reserved: 2025-03-28T11:00:39.752Z

Link: CVE-2025-31450

cve-icon Vulnrichment

Updated: 2025-03-28T14:45:50.646Z

cve-icon NVD

Status : Deferred

Published: 2025-03-28T12:15:17.677

Modified: 2026-04-23T15:27:50.993

Link: CVE-2025-31450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T03:30:07Z

Weaknesses