Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content Manager Light content-manager-light allows Stored XSS.This issue affects Content Manager Light: from n/a through <= 3.2.
Published: 2025-04-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stored Cross‑Site Scripting flaw caused by improper neutralization of user input when generating a web page. An attacker can embed malicious JavaScript that is saved in the database and executed in the browser of any user viewing the affected content. Based on the description, it is inferred that the potential impact includes theft of session cookies, credential leakage, defacement, or the execution of additional malicious actions in the victim’s context. The weakness is identified as CWE‑79.

Affected Systems

All installations of OTWthemes Content Manager Light on WordPress that are version 3.2 or earlier are affected. Sites that rely on this plugin to publish or manage content may be vulnerable if the plugin’s content fields are not properly sanitized.

Risk and Exploitability

The CVSS score of 6.5 reflects a medium severity vulnerability. The EPSS score of less than 1% indicates that exploitation is considered unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited in the wild yet. Attackers may achieve exploitation by accessing the content creation or editing interface, but the exact prerequisites are not detailed; Based on the description, it is inferred that the likely attack vector is through any input that is stored and later rendered without proper sanitization.

Generated by OpenCVE AI on May 2, 2026 at 02:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OTWthemes Content Manager Light to version 3.3 or later, where the stored XSS issue is fixed.
  • Restrict content editing privileges to administrators only, preventing potential attackers from adding malicious input.
  • Deploy a web application firewall or Content Security Policy to block reflected or stored XSS payloads.
  • Monitor site logs for abnormal content entries and perform regular security scans.

Generated by OpenCVE AI on May 2, 2026 at 02:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9250 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content Manager Light allows Stored XSS. This issue affects Content Manager Light: from n/a through 3.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content Manager Light allows Stored XSS. This issue affects Content Manager Light: from n/a through 3.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content Manager Light content-manager-light allows Stored XSS.This issue affects Content Manager Light: from n/a through <= 3.2.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content Manager Light allows Stored XSS. This issue affects Content Manager Light: from n/a through 3.2.
Title WordPress Content Manager Light plugin <= 3.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.517Z

Reserved: 2025-04-01T13:19:46.769Z

Link: CVE-2025-31770

cve-icon Vulnrichment

Updated: 2025-04-01T19:45:37.954Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:14.127

Modified: 2026-04-23T15:28:15.457

Link: CVE-2025-31770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T02:45:32Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')