Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpshopee Awesome Logos awesome-logos allows Reflected XSS.This issue affects Awesome Logos: from n/a through <= 1.2.
Published: 2025-04-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Awesome Logos plugin allows an attacker to inject arbitrary script into web pages that reflect user supplied input. Because the input is not properly sanitized when generating the page, a malicious actor can deliver JavaScript that executes in the context of the website visitor, potentially hijacking sessions, defacing content, or stealing credentials. This flaw is a classic example of Improper Neutralization of Input During Web Page Generation – a type of CWE‑79 weakness. The impact is limited to the execution of attacker‑supplied code in the victim’s browser but represents a serious compromise of confidentiality, integrity, and trust for affected users.

Affected Systems

The affected product is the WordPress Awesome Logos plugin released by wpshopee, with versions up through 1.2. No specific sub‑version details beyond the <= 1.2 boundary are provided, though all installations of any historical release are vulnerable. This plugin is typically deployed on WordPress sites, so any site that has not upgraded beyond version 1.2 is at risk.

Risk and Exploitability

The CVSS score of 7.1 classifies the flaw as High severity, but the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability can be triggered via a normal web interface that includes reflective input, so the attack vector is web, remote. As the flaw is not listed in CISA’s KEV catalog, no known, widespread exploitation has been reported yet, but the potential for targeted attacks remains. Administrators should be aware that an attacker who can direct users to a crafted URL could immediately compromise their browsers.

Generated by OpenCVE AI on May 1, 2026 at 00:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Awesome Logos to the latest version that eliminates the reflected XSS flaw
  • If an upgrade is not immediately possible, restrict or validate all query parameters and form inputs that reflect into the page to ensure only whitelisted content is displayed
  • Deploy a Web Application Firewall or configure the existing WAF to block or sanitize JavaScript payloads in incoming requests to reduce the window of exploitation

Generated by OpenCVE AI on May 1, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14728 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpshopee Awesome Logos allows Reflected XSS. This issue affects Awesome Logos: from n/a through 1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpshopee Awesome Logos allows Reflected XSS. This issue affects Awesome Logos: from n/a through 1.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpshopee Awesome Logos awesome-logos allows Reflected XSS.This issue affects Awesome Logos: from n/a through <= 1.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 03 Apr 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpshopee Awesome Logos allows Reflected XSS. This issue affects Awesome Logos: from n/a through 1.2.
Title WordPress Awesome Logos plugin <= 1.2 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:15.851Z

Reserved: 2025-04-01T13:21:40.753Z

Link: CVE-2025-31899

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-04-03T14:15:42.023

Modified: 2026-04-23T15:28:30.787

Link: CVE-2025-31899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T01:00:05Z

Weaknesses