Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in feedify Feedify – Web Push Notifications push-notification-by-feedify allows Reflected XSS.This issue affects Feedify – Web Push Notifications: from n/a through <= 2.4.5.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during web page generation in the Feedify – Web Push Notifications plugin allows a reflected cross‑site scripting (XSS) vulnerability. An attacker can embed malicious JavaScript in reflected input fields or URLs, causing it to run in the browsers of any user who visits the crafted request. This can lead to theft of session cookies, credential hijacking, defacement, or the execution of other malicious actions within the victim’s context.

Affected Systems

The affected product is the WordPress plugin Feedify – Web Push Notifications, produced by feedify. All plugin versions from the earliest published through version 2.4.5 are susceptible. Sites that have installed any of these versions are at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity for this reflected XSS flaw, but the EPSS score of less than 1 % suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a crafted URL or input that includes a malicious script; a vulnerability, not a privilege escalation, allows an unauthenticated or logged‑in visitor to trigger the injection. Given the lack of advanced prerequisites, the attack surface is broad but the low exploitation probability means immediate attention is still warranted.

Generated by OpenCVE AI on April 30, 2026 at 21:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Feedify – Web Push Notifications plugin to the latest version that fixes the XSS vulnerability; if an update is not yet available, remove the plugin entirely from the site.
  • Implement input validation by ensuring that any user‑supplied data processed by the plugin is properly escaped or sanitized following WordPress best practices.
  • Deploy a web application firewall rule to detect and block suspicious script payloads in query parameters or form data associated with the plugin’s endpoints.

Generated by OpenCVE AI on April 30, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11672 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in feedify Feedify – Web Push Notifications allows Reflected XSS. This issue affects Feedify – Web Push Notifications: from n/a through 2.4.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in feedify Feedify – Web Push Notifications allows Reflected XSS. This issue affects Feedify – Web Push Notifications: from n/a through 2.4.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in feedify Feedify – Web Push Notifications push-notification-by-feedify allows Reflected XSS.This issue affects Feedify – Web Push Notifications: from n/a through <= 2.4.5.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in feedify Feedify – Web Push Notifications allows Reflected XSS. This issue affects Feedify – Web Push Notifications: from n/a through 2.4.5.
Title WordPress Feedify – Web Push Notifications plugin <= 2.4.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:23.793Z

Reserved: 2025-04-09T11:19:50.088Z

Link: CVE-2025-32540

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:42.550

Modified: 2026-04-23T15:29:04.317

Link: CVE-2025-32540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:00:08Z

Weaknesses