Description
The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ parameter in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2025-05-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

Network Posts Extended, a WordPress plugin, has a stored cross‑site scripting vulnerability caused by the post_height parameter. The plugin does not properly sanitize or escape this input, allowing authenticated users with Contributor or higher privileges to inject arbitrary JavaScript into posts. This injected script executes in the browsers of any user who views the affected post, potentially compromising confidentiality and enabling session hijacking or defacement. The weakness is classified as CWE‑79. (The potential for confidentiality compromise, session hijacking, and defacement is inferred from typical XSS behavior and not explicitly stated in the description.)

Affected Systems

Affected systems are any installations of the Network Posts Extended plugin from vendor JohnzenaUSA, specifically all versions up to and including 7.7.1. Any WordPress site using these versions is at risk if a Contributor‑level user submits posts that use the post_height parameter.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. EPSS is less than 1 %, meaning exploitation is unlikely according to current data, and the issue is not listed in the CISA KEV catalog. The attack vector requires authenticated access and a role of Contributor or higher, so it is not remote; it relies on the ability to edit or place posts. Once the attacker injects the script, it persists and will run for any visitor to the page, potentially until the plugin is upgraded or the content is cleaned. (The analysis that the script might lead to confidentiality compromise or session hijacking is inferred based on common XSS effects.)

Generated by OpenCVE AI on April 22, 2026 at 01:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Network Posts Extended to version 7.8.0 or later to remove the vulnerability.
  • Restrict Contributor+ roles to trusted users only and monitor for unusual post edits as a temporary workaround.
  • Deploy a Content Security Policy that blocks execution of inline JavaScript on post pages to mitigate the impact of existing injections.

Generated by OpenCVE AI on April 22, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-16080 The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ parameter in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

Wed, 21 May 2025 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 21 May 2025 09:30:00 +0000

Type Values Removed Values Added
Description The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ parameter in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Network Posts Extended <= 7.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_height Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:57:37.155Z

Reserved: 2025-04-16T21:00:11.045Z

Link: CVE-2025-3750

cve-icon Vulnrichment

Updated: 2025-05-21T10:11:57.418Z

cve-icon NVD

Status : Deferred

Published: 2025-05-21T12:16:21.447

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-3750

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T01:45:05Z

Weaknesses