Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Ally pojo-accessibility allows Stored XSS.This issue affects Ally: from n/a through <= 3.1.0.
Published: 2025-04-09
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation allows a stored cross‑site scripting flaw in the WordPress One Click Accessibility plugin. If an attacker injects malicious script that is stored by the plugin, that script will later be served to any user who views the affected page, providing the attacker the ability to steal session cookies, deface content or perform further client‑side attacks. Based on the description, the likely attack vector is an input field within the plugin’s configuration or content entry interface that accepts unsanitized data. The vulnerability was rated CVSS 5.9.

Affected Systems

The flaw affects the Elementor Ally "pojo‑accessibility" plugin from the earliest available release up through version 3.1.0. No other vendor or product versions are listed.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate impact. The EPSS score of less than 1% suggests that exploitation of this vulnerability is currently unlikely in the wild, and the vulnerability is not currently catalogued in CISA’s KEV list. If an attacker can supply data through the plugin’s input paths, the stored script will be delivered to all site visitors, potentially leading to compromise of user accounts or defacement of the site. However, because the vulnerability requires data to be stored and then displayed, it is less likely to be exploited by arbitrary unauthenticated users unless the plugin exposes such input to them. The overall risk to a typical WordPress site is moderate, but it warrants prompt update to avoid accidental exploitation.

Generated by OpenCVE AI on May 1, 2026 at 00:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WordPress One Click Accessibility plugin to a version newer than 3.1.0.
  • If an immediate update is infeasible, restrict the plugin’s configuration and content entry capabilities to administrators only to limit who can inject data.
  • Deploy a Web Application Firewall rule or content‑security‑policy header that blocks or escapes unsanitized script payloads entered via the plugin’s inputs.

Generated by OpenCVE AI on May 1, 2026 at 00:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10575 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor One Click Accessibility allows Stored XSS. This issue affects One Click Accessibility: from n/a through 3.1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor One Click Accessibility allows Stored XSS. This issue affects One Click Accessibility: from n/a through 3.1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Ally pojo-accessibility allows Stored XSS.This issue affects Ally: from n/a through <= 3.1.0.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 09 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor One Click Accessibility allows Stored XSS. This issue affects One Click Accessibility: from n/a through 3.1.0.
Title WordPress One Click Accessibility plugin <= 3.1.0 - Cross-Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:26.832Z

Reserved: 2025-04-09T11:20:57.809Z

Link: CVE-2025-32640

cve-icon Vulnrichment

Updated: 2025-04-09T17:42:31.220Z

cve-icon NVD

Status : Deferred

Published: 2025-04-09T17:15:49.360

Modified: 2026-04-23T15:29:15.843

Link: CVE-2025-32640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T00:15:04Z

Weaknesses