Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ContentBot.ai ContentBot AI Writer content-bot allows Stored XSS.This issue affects ContentBot AI Writer: from n/a through <= 1.2.4.
Published: 2025-04-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ContentBot AI Writer, a WordPress plugin, contains an improper neutralization of input during web page generation that allows attackers to inject malicious scripts that persist in stored content. This stored XSS flaw can be leveraged to steal user credentials, hijack sessions, deface the site, or serve additional malware to visitors. The weakness is a classic CWE‑79 input verification defect that compromises client‑side confidentiality and integrity.

Affected Systems

WordPress installations running ContentBot.ai ContentBot AI Writer plugin version 1.2.4 or earlier are vulnerable. The flaw applies to any instance where the plugin’s content or comment fields accept untrusted input without proper sanitization.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate impact, while the EPSS score of less than 1% suggests a low probability of exploitation at the moment. It is not currently listed in the CISA KEV catalog. The likely attack vector is via the WordPress admin interface or front‑end forms that submit data to the plugin; an attacker may use these inputs to store malicious scripts that render in browsers of site visitors. Without an active exploit, the risk remains moderate, but the presence of a stored XSS endpoint means that any authenticated user could insert malicious payloads that affect all recipients.

Generated by OpenCVE AI on May 1, 2026 at 11:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ContentBot AI Writer plugin to version 1.2.5 or later, which includes input sanitization fixes for stored XSS
  • Apply a web application firewall rule or equivalent security plugin setting to detect and block script tags or other executable payloads submitted through the plugin's forms
  • Temporarily disable the plugin’s content creation or comment features for non‑admin users until the patch is applied

Generated by OpenCVE AI on May 1, 2026 at 11:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9227 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ContentBot.ai ContentBot AI Writer allows Stored XSS. This issue affects ContentBot AI Writer: from n/a through 1.2.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ContentBot.ai ContentBot AI Writer allows Stored XSS. This issue affects ContentBot AI Writer: from n/a through 1.2.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ContentBot.ai ContentBot AI Writer content-bot allows Stored XSS.This issue affects ContentBot AI Writer: from n/a through <= 1.2.4.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ContentBot.ai ContentBot AI Writer allows Stored XSS. This issue affects ContentBot AI Writer: from n/a through 1.2.4.
Title WordPress ContentBot AI Writer plugin <= 1.2.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:13.484Z

Reserved: 2025-04-01T13:20:24.607Z

Link: CVE-2025-31818

cve-icon Vulnrichment

Updated: 2025-04-01T19:15:32.703Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:21.803

Modified: 2026-04-23T15:28:21.323

Link: CVE-2025-31818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')