Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSight WPCasa wpcasa allows Stored XSS.This issue affects WPCasa: from n/a through <= 1.3.2.
Published: 2025-04-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to store malicious JavaScript in the WordPress WPCasa plugin, which is then executed in the browser of any user who views the affected content. This Stored XSS flaw arises from insufficient input sanitization during web page generation and can be used to steal session cookies, deface pages, or redirect users to malicious sites.

Affected Systems

The flaw exists in the WPSight WPCasa plugin for WordPress versions up to and including 1.3.2. Site owners using any of these versions are potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, yet the EPSS score of less than 1% shows a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to inject code into a location that persists on the site, typically via a form or content field, and then entice other users to view the modified page. Successful exploitation would grant the attacker the privileges of the victim’s browser session, enabling credential theft or defacement.

Generated by OpenCVE AI on April 30, 2026 at 22:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest version of the WPCasa plugin, which removes the XSS flaw
  • If an upgrade is not immediately possible, temporarily disable or delete the affected plugin to prevent exploitation
  • Configure a web application firewall or content security policy to block or escape stored malicious scripts

Generated by OpenCVE AI on April 30, 2026 at 22:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11292 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSight WPCasa allows Stored XSS. This issue affects WPCasa: from n/a through 1.3.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSight WPCasa allows Stored XSS. This issue affects WPCasa: from n/a through 1.3.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSight WPCasa wpcasa allows Stored XSS.This issue affects WPCasa: from n/a through <= 1.3.2.
Title WordPress WPCasa <= 1.3.2 - Cross Site Scripting (XSS) Vulnerability WordPress WPCasa plugin <= 1.3.2 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 16 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 12:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSight WPCasa allows Stored XSS. This issue affects WPCasa: from n/a through 1.3.2.
Title WordPress WPCasa <= 1.3.2 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:34.977Z

Reserved: 2025-04-16T06:26:36.913Z

Link: CVE-2025-39575

cve-icon Vulnrichment

Updated: 2025-04-16T13:48:49.704Z

cve-icon NVD

Status : Deferred

Published: 2025-04-16T13:15:50.183

Modified: 2026-04-23T15:29:49.083

Link: CVE-2025-39575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:00:04Z

Weaknesses