Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in serpednet SERPed.net serped-net allows Reflected XSS.This issue affects SERPed.net: from n/a through <= 4.6.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can craft a malicious URL that injects script code into the SERPed.net plugin’s response. Because the plugin does not neutralize user input before rendering, reflected cross‑site scripting occurs. This flaw can allow execution of arbitrary JavaScript in a user’s browser, leading to credential theft, session hijacking, or defacement. The weakness is identified as CWE-79.

Affected Systems

The vulnerability is present in the WordPress SERPed.net plugin supplied by the SERPed.net vendor. Any site running a version of SERPed.net up to and including 4.6 is affected. No other products are listed.

Risk and Exploitability

The CVSS score indicates high severity (score 7.1), but the EPSS score of less than 1% suggests a low probability of being exploited in the wild at present. The flaw is not listed in the CISA KEV catalog, indicating it has not yet been widely used. The likely attack vector is remote: an attacker can send a crafted link to a vulnerable user, who opens it in a browser and executes the injected script. No authentication is required; the vulnerability is exploitable via a reflected request.

Generated by OpenCVE AI on May 1, 2026 at 09:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SERPed.net WordPress plugin to a version newer than 4.6 once an updated release is available from the vendor.
  • If upgrading is not feasible, remove or disable the SERPed.net plugin until a patched version is available.
  • Implement a site‑wide Content Security Policy that disallows inline scripts and scripts from unknown origins to mitigate the impact if an attacker successfully injects code.

Generated by OpenCVE AI on May 1, 2026 at 09:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11723 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in serpednet SERPed.net allows Reflected XSS. This issue affects SERPed.net: from n/a through 4.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in serpednet SERPed.net allows Reflected XSS. This issue affects SERPed.net: from n/a through 4.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in serpednet SERPed.net serped-net allows Reflected XSS.This issue affects SERPed.net: from n/a through <= 4.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in serpednet SERPed.net allows Reflected XSS. This issue affects SERPed.net: from n/a through 4.6.
Title WordPress SERPed.net Plugin <= 4.6 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:26.511Z

Reserved: 2025-04-09T11:21:04.030Z

Link: CVE-2025-32651

cve-icon Vulnrichment

Updated: 2025-04-17T18:08:34.797Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:49.167

Modified: 2026-04-23T15:29:17.050

Link: CVE-2025-32651

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:00:12Z

Weaknesses