Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.This issue affects Sirv: from n/a through <= 7.5.3.
Published: 2025-04-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Sirv CDN and Image Hosting plugin allows an attacker to perform stored Cross‑Site Scripting by injecting malicious input that is not properly neutralized before rendering in web pages. This can result in arbitrary script execution in the browsers of any user who views content processed by the plugin. The impact includes potential data theft, session hijacking, and defacement of sites that rely on the affected plugin.

Affected Systems

Sirv CDN and Image Hosting: Sirv Plug‑in versions up to 7.5.3 are affected. Any WordPress installation using these versions is at risk.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. With an EPSS score of less than 1%, the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by inserting malicious content into fields managed by the plugin, which is then stored and served to visitors. The attack vector is likely via the plugin’s input mechanisms, requiring the attacker to inject data that results in a rogue script being executed when a page is rendered.

Generated by OpenCVE AI on April 30, 2026 at 21:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Sirv plugin to version 7.5.4 or later to remove the stored XSS flaw
  • If an upgrade is not immediately possible, thoroughly review and sanitize any user‑supplied data that the plugin stores, removing any suspicious script fragments
  • Consider disabling or uninstalling the Sirv plugin until a patched version is available to prevent further exploitation

Generated by OpenCVE AI on April 30, 2026 at 21:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12302 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv allows Stored XSS. This issue affects Sirv: from n/a through 7.5.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv allows Stored XSS. This issue affects Sirv: from n/a through 7.5.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.This issue affects Sirv: from n/a through <= 7.5.3.
Title WordPress Sirv <= 7.5.3 - Cross Site Scripting (XSS) Vulnerability WordPress Sirv plugin <= 7.5.3 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Wed, 30 Apr 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Sirv
Sirv sirv
CPEs cpe:2.3:a:sirv:sirv:*:*:*:*:*:wordpress:*:*
Vendors & Products Sirv
Sirv sirv

Tue, 22 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Apr 2025 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv allows Stored XSS. This issue affects Sirv: from n/a through 7.5.3.
Title WordPress Sirv <= 7.5.3 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:36.771Z

Reserved: 2025-04-22T08:46:38.826Z

Link: CVE-2025-46233

cve-icon Vulnrichment

Updated: 2025-04-22T14:19:40.581Z

cve-icon NVD

Status : Modified

Published: 2025-04-22T10:15:16.567

Modified: 2026-04-23T15:29:55.167

Link: CVE-2025-46233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T21:45:26Z

Weaknesses