Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rico Macchi WP Featured Screenshot wp-featured-screenshot allows Reflected XSS.This issue affects WP Featured Screenshot: from n/a through <= 1.3.
Published: 2025-04-17
Score: 7.1 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of user input during web page generation in the WP Featured Screenshot plugin leads to a reflected cross‑site scripting vulnerability. Malicious payloads injected via query parameters or form submissions can execute arbitrary JavaScript in the context of a user’s browser when the plugin renders the requested page. This could enable attackers to steal session cookies, deface content, or redirect users to malicious sites, compromising the confidentiality, integrity, and availability of the website and its visitors.

Affected Systems

Rico Macchi’s WP Featured Screenshot plugin, versions up to and including 1.3, is affected. The flaw exists in the plugin’s handling of input when generating previews or screenshots, permitting reflected XSS across all installations using the vulnerable versions.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, but the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not yet listed in CISA KEV. Based on the description, the likely attack vector is a remote HTTP request targeting the plugin’s endpoints, where an attacker supplies malicious content that is reflected back in the page. If exploited, the attacker could execute arbitrary scripts in a victim’s browser during normal interaction with the site.

Generated by OpenCVE AI on April 30, 2026 at 21:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP Featured Screenshot to a version newer than 1.3 or disable the plugin if it is no longer needed.
  • Implement a web application firewall rule that detects and blocks reflected XSS payloads targeting the plugin’s input parameters.
  • Configure a strict Content Security Policy to restrict script execution and mitigate any residual attack vectors.

Generated by OpenCVE AI on April 30, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11679 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rico Macchi WP Featured Screenshot allows Reflected XSS. This issue affects WP Featured Screenshot: from n/a through 1.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rico Macchi WP Featured Screenshot allows Reflected XSS. This issue affects WP Featured Screenshot: from n/a through 1.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rico Macchi WP Featured Screenshot wp-featured-screenshot allows Reflected XSS.This issue affects WP Featured Screenshot: from n/a through <= 1.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rico Macchi WP Featured Screenshot allows Reflected XSS. This issue affects WP Featured Screenshot: from n/a through 1.3.
Title WordPress WP Featured Screenshot Plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:24.068Z

Reserved: 2025-04-09T11:20:02.681Z

Link: CVE-2025-32557

cve-icon Vulnrichment

Updated: 2025-04-17T18:06:41.224Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:43.517

Modified: 2026-04-23T15:29:06.100

Link: CVE-2025-32557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:00:08Z

Weaknesses