Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dxladner Client Showcase client-showcase allows Stored XSS.This issue affects Client Showcase: from n/a through <= 1.2.0.
Published: 2025-04-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation enables attackers to store malicious scripts that are later served to site visitors. The stored XSS flaw, identified as CWE‑79, allows an attacker to embed arbitrary JavaScript into pages generated by the Client Showcase plugin. When a legitimate user views the affected content, the browser executes the injected script, which can lead to cookie theft, session hijacking, defacement or delivery of malware. Due to the stored nature of the payload, the impact can persist across sessions and affect any user who views the compromised content.

Affected Systems

The vulnerability affects the Client Showcase plugin developed by dxladner. All versions from the earliest release through version 1.2.0 are vulnerable. Users running the plugin in WordPress installations that have not upgraded beyond current 1.2.0 are impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation. The likely attack vector is via the plugin’s form fields or any interface that accepts user‑supplied content, which the plugin stores without proper sanitization. An attacker can simply embed a malicious payload into the stored data; when the data is later rendered by the plugin, the payload will be executed in the browsers of all users who view that content.

Generated by OpenCVE AI on May 1, 2026 at 02:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Client Showcase to a version newer than 1.2.0 to remove the stored XSS flaw.
  • If an upgrade is not immediately possible, disable the Client Showcase plugin until a patched version is available to prevent further exploitation.
  • Scan existing stored content for injected JavaScript and cleanse any dirty data before reloading it into the site.

Generated by OpenCVE AI on May 1, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9282 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dxladner Client Showcase allows Stored XSS. This issue affects Client Showcase: from n/a through 1.2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dxladner Client Showcase allows Stored XSS. This issue affects Client Showcase: from n/a through 1.2.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dxladner Client Showcase client-showcase allows Stored XSS.This issue affects Client Showcase: from n/a through <= 1.2.0.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dxladner Client Showcase allows Stored XSS. This issue affects Client Showcase: from n/a through 1.2.0.
Title WordPress Client Showcase plugin <= 1.2.0 - Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:11.359Z

Reserved: 2025-04-01T13:18:48.161Z

Link: CVE-2025-31737

cve-icon Vulnrichment

Updated: 2025-04-01T20:32:56.982Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:09.770

Modified: 2026-04-23T15:28:09.160

Link: CVE-2025-31737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:30:06Z

Weaknesses