Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twice Commerce Twice Commerce embed-rentle allows DOM-Based XSS.This issue affects Twice Commerce: from n/a through <= 1.3.1.
Published: 2025-03-31
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation in the embed‑rentle component of the Twice Commerce plugin allows an attacker to inject arbitrary scripts into browsers that view affected pages. The vulnerability is a DOM‑based XSS flaw classified as CWE‑79 and carries a CVSS score of 6.5, indicating a moderate severity if exploited.

Affected Systems

The flaw affects the Twice Commerce WordPress plugin, specifically the embed‑rentle feature, in all versions from the earliest release through 1.3.1. Any WordPress site that has installed or updated the plugin to a version no higher than 1.3.1 is potentially vulnerable, regardless of other configuration settings.

Risk and Exploitability

The EPSS score of less than 1 % shows a low current likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 6.5 highlights moderate severity. Exploitation requires supplying malicious input that is reflected into the page for any user who accesses the affected embed‑rentle page.

Generated by OpenCVE AI on May 2, 2026 at 02:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Twice Commerce plugin to a version newer than 1.3.1, or uninstall the plugin if no fix is available.
  • If upgrading is not possible, disable or remove the embed‑rentle functionality by adjusting the plugin settings or removing related code.
  • After applying a fix, run an interactive XSS scan or test against the embed‑rentle pages to verify the vulnerability is eliminated.

Generated by OpenCVE AI on May 2, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8807 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twice Commerce Twice Commerce allows DOM-Based XSS. This issue affects Twice Commerce: from n/a through 1.3.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twice Commerce Twice Commerce allows DOM-Based XSS. This issue affects Twice Commerce: from n/a through 1.3.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twice Commerce Twice Commerce embed-rentle allows DOM-Based XSS.This issue affects Twice Commerce: from n/a through <= 1.3.1.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 31 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twice Commerce Twice Commerce allows DOM-Based XSS. This issue affects Twice Commerce: from n/a through 1.3.1.
Title WordPress Twice Commerce plugin <= 1.3.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:08.587Z

Reserved: 2025-03-31T10:05:22.814Z

Link: CVE-2025-31543

cve-icon Vulnrichment

Updated: 2025-03-31T14:12:28.538Z

cve-icon NVD

Status : Deferred

Published: 2025-03-31T13:15:48.360

Modified: 2026-04-23T15:27:56.107

Link: CVE-2025-31543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T03:00:13Z

Weaknesses