Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Lock Your Updates lock-your-updates allows Reflected XSS.This issue affects Lock Your Updates: from n/a through <= 1.1.
Published: 2025-04-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation in the Lock Your Updates plugin allows attackers to embed malicious scripts in the plugin's output, creating a reflected Cross-Site Scripting vulnerability.

Affected Systems

The vulnerability affects the WordPress plugin Lock Your Updates, developed by Rachel Cherry, for all released versions up to and including 1.1.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity, while an EPSS score of less than 1% suggests low but non-zero exploitation likelihood; the vulnerability is not listed in CISA's KEV catalog. Attackers can leverage this flaw by constructing URLs that trigger the plugin's output step, which then reflects user‑supplied data without proper encoding. A successful exploitation can execute arbitrary scripts in the context of site visitors or administrators, enabling session hijacking, defacement, or theft of credentials.

Generated by OpenCVE AI on April 30, 2026 at 23:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Lock Your Updates plugin to a fixed version newer than 1.1.
  • If an update is not available, disable or delete the plugin to remove the vulnerable code.
  • Implement a strict Content Security Policy that disallows inline scripts to mitigate the impact of any remaining reflected XSS payloads.

Generated by OpenCVE AI on April 30, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10772 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Lock Your Updates allows Reflected XSS. This issue affects Lock Your Updates: from n/a through 1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Lock Your Updates allows Reflected XSS. This issue affects Lock Your Updates: from n/a through 1.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Lock Your Updates lock-your-updates allows Reflected XSS.This issue affects Lock Your Updates: from n/a through <= 1.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Apr 2025 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Lock Your Updates allows Reflected XSS. This issue affects Lock Your Updates: from n/a through 1.1.
Title WordPress Lock Your Updates Plugin <= 1.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:23.640Z

Reserved: 2025-04-09T11:19:50.087Z

Link: CVE-2025-32537

cve-icon Vulnrichment

Updated: 2025-04-11T15:28:43.002Z

cve-icon NVD

Status : Deferred

Published: 2025-04-11T09:15:25.703

Modified: 2026-04-23T15:29:03.983

Link: CVE-2025-32537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:15:05Z

Weaknesses