Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS Twitter Follow Button bns-twitter-follow-button allows DOM-Based XSS.This issue affects BNS Twitter Follow Button: from n/a through <= 0.3.8.
Published: 2025-05-12
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The BNS Twitter Follow Button plugin contains a DOM‑based cross‑site scripting flaw that permits an attacker to inject malicious JavaScript into a WordPress page. Failure to neutralize user‑generated input during page rendering enables the execution of arbitrary client‑side code when a visitor loads a page that includes the plugin. This can lead to theft of session cookies, credential hijacking, defacement, or malicious actions performed in the victim’s browser, and is identified as CWE‑79.

Affected Systems

The vulnerability applies to the Edward Caissie BNS Twitter Follow Button WordPress plugin, affecting all installations of version 0.3.8 and earlier. Any WordPress site that hosts the vulnerable plugin version is at risk, regardless of the core WordPress release.

Risk and Exploitability

The CVSS score of 6.5 classifies the flaw as moderate severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation in the near term. The weakness is not listed in the CISA KEV catalog. Exploitability requires a victim to visit a page that loads the malicious script through the plugin, meaning a remote, user‑interaction attack path. Because the flaw is client‑side, it does not compromise server infrastructure, but it can compromise individual users’ browsers and lead to credential theft or other client‑side damage.

Generated by OpenCVE AI on April 30, 2026 at 13:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade the BNS Twitter Follow Button plugin to at least version 0.3.9 if available.
  • If a fix is not yet released, permanently delete or disable the plugin to remove the vulnerable code path.
  • Run a file integrity check on the plugin’s directory to ensure that no malicious scripts have been injected or modified during the update process.

Generated by OpenCVE AI on April 30, 2026 at 13:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14298 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS Twitter Follow Button allows DOM-Based XSS.This issue affects BNS Twitter Follow Button: from n/a through 0.3.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS Twitter Follow Button allows DOM-Based XSS.This issue affects BNS Twitter Follow Button: from n/a through 0.3.8. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS Twitter Follow Button bns-twitter-follow-button allows DOM-Based XSS.This issue affects BNS Twitter Follow Button: from n/a through <= 0.3.8.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 12 May 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 May 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS Twitter Follow Button allows DOM-Based XSS.This issue affects BNS Twitter Follow Button: from n/a through 0.3.8.
Title WordPress BNS Twitter Follow Button plugin <= 0.3.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:45.522Z

Reserved: 2025-05-07T09:55:31.577Z

Link: CVE-2025-47578

cve-icon Vulnrichment

Updated: 2025-05-12T18:00:26.789Z

cve-icon NVD

Status : Deferred

Published: 2025-05-12T16:15:25.720

Modified: 2026-04-23T15:30:32.110

Link: CVE-2025-47578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T13:15:37Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')