Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BooSpot Boo Recipes boo-recipes allows Stored XSS.This issue affects Boo Recipes: from n/a through <= 2.4.1.
Published: 2025-04-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of Input During Web Page Generation allows attackers to inject malicious JavaScript that is stored and subsequently served to all site visitors. Once executed, the script can hijack user sessions, deface the site, or exfiltrate sensitive data. The weakness is identified as CWE‑79, a classic input validation flaw that enables transmitted code to run in the victim’s browser environment.

Affected Systems

The vulnerability appears in the BooSpot Boo Recipes WordPress plugin, affecting all releases from the earliest version through 2.4.1. No specific sub‑versions are listed, so the entire 2.4.1 release family is impacted. Users on older releases are also potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a high impact when exploited, while an EPSS score of less than 1 % signals a relatively low probability of exploitation at the time of analysis. The vulnerability is not currently listed in the CISA KEV catalog. An attacker can typically target the plugin via web requests that store data (e.g., recipe creation forms) and rely on the site’s visitors to trigger the malicious script. While precise prerequisites are not detailed in the description, basic web access to the plugin’s interfaces is required.

Generated by OpenCVE AI on May 1, 2026 at 02:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest version of the Boo Recipes plugin (any release newer than 2.4.1).
  • Restrict administrative access to the plugin and any interfaces that accept user input, ensuring only trusted users can create or modify content.
  • Implement a Web Application Firewall or custom input sanitization rules to detect and block suspicious script payloads in form submissions.

Generated by OpenCVE AI on May 1, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9271 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BooSpot Boo Recipes allows Stored XSS. This issue affects Boo Recipes: from n/a through 2.4.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BooSpot Boo Recipes allows Stored XSS. This issue affects Boo Recipes: from n/a through 2.4.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BooSpot Boo Recipes boo-recipes allows Stored XSS.This issue affects Boo Recipes: from n/a through <= 2.4.1.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BooSpot Boo Recipes allows Stored XSS. This issue affects Boo Recipes: from n/a through 2.4.1.
Title WordPress Boo Recipes plugin <= 2.4.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.286Z

Reserved: 2025-04-01T13:19:38.348Z

Link: CVE-2025-31759

cve-icon Vulnrichment

Updated: 2025-04-01T20:32:34.511Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:12.517

Modified: 2026-04-23T15:28:14.107

Link: CVE-2025-31759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:30:06Z

Weaknesses