Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dev02ali Easy Post Duplicator easy-post-duplicator allows Reflected XSS.This issue affects Easy Post Duplicator: from n/a through <= 1.0.1.
Published: 2025-04-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an instance of improper neutralization of input during web page generation, allowing an attacker to inject and execute arbitrary JavaScript code in the browser of a user who views a contaminated page. The specific weakness, classified as CWE‑79, can be leveraged to steal session cookies, deface the site, or redirect users to malicious domains. Because the exploit relies on reflected input, it does not require persistent changes to the site’s codebase, making it relatively easy to trigger if the vulnerable code path is accessible.

Affected Systems

WordPress installations that have the dev02ali Easy Post Duplicator plugin version 1.0.1 or earlier installed are affected. No other plugins or WordPress core versions are impacted by this flaw.

Risk and Exploitability

The CVSS score of 7.1 places this issue in the high‑severity range. The EPSS score is listed as less than 1 %, suggesting that, while exploitation is possible, it is not currently widespread in the wild. The vulnerability is not listed in the CISA KEV catalog, which also indicates an absence of known large‑scale exploits. The likely attack vector is remote via a malicious link or form that a user clicks or submits, after which the injected script runs in the victim’s browser.

Generated by OpenCVE AI on April 30, 2026 at 23:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Easy Post Duplicator to a version newer than 1.0.1; if no update is available, uninstall or replace the plugin.
  • Deactivate the plugin’s functionality that processes user input susceptible to XSS, or configure it to sanitize all external data before rendering.
  • Deploy a site‑wide web application firewall or add comprehensive CSP and XSS filters to intercept and block malicious scripts before they reach users.

Generated by OpenCVE AI on April 30, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10765 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dev02ali Easy Post Duplicator allows Reflected XSS. This issue affects Easy Post Duplicator: from n/a through 1.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dev02ali Easy Post Duplicator allows Reflected XSS. This issue affects Easy Post Duplicator: from n/a through 1.0.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dev02ali Easy Post Duplicator easy-post-duplicator allows Reflected XSS.This issue affects Easy Post Duplicator: from n/a through <= 1.0.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Apr 2025 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dev02ali Easy Post Duplicator allows Reflected XSS. This issue affects Easy Post Duplicator: from n/a through 1.0.1.
Title WordPress Easy Post Duplicator Plugin <= 1.0.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:23.728Z

Reserved: 2025-04-09T11:19:50.087Z

Link: CVE-2025-32538

cve-icon Vulnrichment

Updated: 2025-04-11T14:28:05.360Z

cve-icon NVD

Status : Deferred

Published: 2025-04-11T09:15:26.007

Modified: 2026-04-23T15:29:04.093

Link: CVE-2025-32538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:15:05Z

Weaknesses