Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biancardi Mixcloud Embed mixcloud-embed allows Stored XSS.This issue affects Mixcloud Embed: from n/a through <= 2.2.0.
Published: 2025-04-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Mixcloud Embed plugin contains a stored cross‑site scripting flaw that fails to properly neutralize user input before rendering it on web pages. This weakness, identified as CWE‑79, allows an attacker to inject arbitrary JavaScript that will execute in the browsers of all users who view the affected content, potentially leading to session hijacking, credential theft, or tampering of page content. The damage is confined to the confidentiality, integrity, and availability of the website’s front‑end, but it can affect all visitors of a compromised site.

Affected Systems

All WordPress installations that include the biancardi Mixcloud Embed plugin version 2.2.0 or earlier are impacted. Any site that has deployed or currently uses one of these affected versions can be susceptible to the stored XSS.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the EPSS score—reported as less than 1%—shows a low likelihood of widespread public exploitation at present. The vulnerability is not listed in CISA’s KEV catalogue, so no active exploitation is documented. Based on the description, it is inferred that an attacker would need to use an interface that accepts user‑supplied data—such as a post editor, shortcode, or form—into the plugin and then play a malicious script that is stored and later served to other users.

Generated by OpenCVE AI on May 1, 2026 at 09:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mixcloud Embed to any version newer than 2.2.0.
  • If an upgrade is not immediately possible, deactivate or uninstall the plugin until a fix is released.
  • Search the site’s database for injected scripts and remove any entries containing dangerous content.

Generated by OpenCVE AI on May 1, 2026 at 09:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12037 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biancardi Mixcloud Embed allows Stored XSS. This issue affects Mixcloud Embed: from n/a through 2.2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biancardi Mixcloud Embed allows Stored XSS. This issue affects Mixcloud Embed: from n/a through 2.2.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biancardi Mixcloud Embed mixcloud-embed allows Stored XSS.This issue affects Mixcloud Embed: from n/a through <= 2.2.0.
Title WordPress Mixcloud Embed <= 2.2.0 - Cross Site Scripting (XSS) Vulnerability WordPress Mixcloud Embed plugin <= 2.2.0 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 24 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biancardi Mixcloud Embed allows Stored XSS. This issue affects Mixcloud Embed: from n/a through 2.2.0.
Title WordPress Mixcloud Embed <= 2.2.0 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:39.602Z

Reserved: 2025-04-24T14:23:02.621Z

Link: CVE-2025-46501

cve-icon Vulnrichment

Updated: 2025-04-24T19:53:03.128Z

cve-icon NVD

Status : Deferred

Published: 2025-04-24T16:15:40.913

Modified: 2026-04-23T15:30:07.537

Link: CVE-2025-46501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T09:15:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')