Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darshan Saroya Color Your Bar color-your-bar allows Stored XSS.This issue affects Color Your Bar: from n/a through <= 2.0.
Published: 2025-05-07
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an improper neutralization of input during web page generation that enables attackers to inject malicious JavaScript into stored data. The stored cross‑site scripting flaw could allow an attacker to execute code in the browsers of any visitor who views the affected content; it is inferred that such code execution could lead to session cookie theft, account hijacking, or defacement, although these specific consequences are not explicitly described in the official description. The weakness is classified as CWE‑79 and poses risks to confidentiality and integrity, though it does not directly affect availability.

Affected Systems

The flaw affects the WordPress plugin Color Your Bar, developed by Darshan Saroya, in versions up through and including 2.0. Any WordPress installation that has this plugin installed and not yet updated to a version later than 2.0 is susceptible.

Risk and Exploitability

The CVSS score of 5.9 places the vulnerability in the medium severity range, but the EPSS score being less than 1% indicates a very low probability of existing exploits in the wild. The issue is not listed in the CISA KEV catalog. Exploitation requires that an attacker have knowledge of the plugin's data entry point to store malicious payloads, so the attack vector is likely through an interface that writes content to the database. Once stored, the payload will run in any end‑user browser that renders the affected pages.

Generated by OpenCVE AI on May 1, 2026 at 08:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Color Your Bar plugin to the latest available version (any release newer than 2.0).
  • If an update is not feasible, disable or deactivate the plugin to prevent further data entry.
  • Deploy a web application firewall or content‑security‑policy header that blocks reflected and stored XSS payloads to provide a temporary protective layer before a permanent fix is applied.

Generated by OpenCVE AI on May 1, 2026 at 08:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13777 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darshan Saroya Color Your Bar allows Stored XSS. This issue affects Color Your Bar: from n/a through 2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darshan Saroya Color Your Bar allows Stored XSS. This issue affects Color Your Bar: from n/a through 2.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darshan Saroya Color Your Bar color-your-bar allows Stored XSS.This issue affects Color Your Bar: from n/a through <= 2.0.
Title WordPress Color Your Bar <= 2.0 - Cross Site Scripting (XSS) Vulnerability WordPress Color Your Bar plugin <= 2.0 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}

epss

{'score': 0.00042}


Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darshan Saroya Color Your Bar allows Stored XSS. This issue affects Color Your Bar: from n/a through 2.0.
Title WordPress Color Your Bar <= 2.0 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:46.877Z

Reserved: 2025-05-07T10:44:15.222Z

Link: CVE-2025-47595

cve-icon Vulnrichment

Updated: 2025-05-07T17:19:50.906Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:16:13.183

Modified: 2026-04-23T15:30:33.953

Link: CVE-2025-47595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')