Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History timeline-event-history allows Stored XSS.This issue affects Timeline Event History: from n/a through <= 3.2.
Published: 2025-03-31
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that allows stored cross‑site scripting within the WordPress Timeline Event History plugin. An attacker can inject malicious JavaScript that will execute in the browsers of any user who views the vulnerable event. It is inferred that such execution could lead to actions such as cookie theft, session hijacking, or defacement, based on typical stored XSS scenarios. The flaw stems from unsanitised input being stored in the event record and later rendered without encoding.

Affected Systems

Affects the wpdiscover Timeline Event History plugin for WordPress, specifically all releases from the earliest available version through 3.2 inclusive. Users running any version of this plugin vulnerable to the flaw should verify the version and upgrade if possible.

Risk and Exploitability

The CVSS score of 6.5 classifies the issue as medium severity, while the EPSS score indicates a very low probability of exploitation (less than 1%). The flaw is not listed in CISA’s KEV catalog. The attack vector is likely an authenticated user with permission to create or edit events, based on the requirement that malicious input be stored in the plugin database. Once an event is injected, any visitor to that event page will be affected. Overall, the risk is moderate. It is inferred that if an attacker exploited the XSS, the impact to compromised users could be significant, such as theft of session cookies or spread of malware.

Generated by OpenCVE AI on May 1, 2026 at 12:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Timeline Event History plugin to a version newer than 3.2 that includes the fix
  • If an upgrade is not immediately possible, restrict access to the event creation and editing capabilities to trusted or privileged users only
  • As a temporary measure, disable the plugin until a patched version is installed

Generated by OpenCVE AI on May 1, 2026 at 12:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8758 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History allows Stored XSS. This issue affects Timeline Event History: from n/a through 3.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History allows Stored XSS. This issue affects Timeline Event History: from n/a through 3.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History timeline-event-history allows Stored XSS.This issue affects Timeline Event History: from n/a through <= 3.2.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 31 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History allows Stored XSS. This issue affects Timeline Event History: from n/a through 3.2.
Title WordPress Timeline Event History plugin <= 3.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:09.718Z

Reserved: 2025-03-31T10:06:04.392Z

Link: CVE-2025-31595

cve-icon Vulnrichment

Updated: 2025-03-31T15:00:16.874Z

cve-icon NVD

Status : Deferred

Published: 2025-03-31T13:15:53.087

Modified: 2026-04-23T15:28:01.987

Link: CVE-2025-31595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:15:17Z

Weaknesses