Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bistromatic N360 | Splash Screen n360-splash-screen allows Stored XSS.This issue affects N360 | Splash Screen: from n/a through <= 1.0.6.
Published: 2025-05-07
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic stored cross‑site scripting flaw that occurs when the N360 | Splash Screen plugin fails to properly neutralize user input before rendering it in web pages. Attackers can inject malicious JavaScript that will be executed in the browsers of any user that views the affected page, enabling session hijacking, cookie theft, or defacement. The impact is confined to the confidentiality and integrity of affected site visitors and those with access to the plugin’s settings, but could be used to poison entire site sessions if an administrator imports the payload through the plugin.

Affected Systems

bistromatic’s N360 | Splash Screen plugin is vulnerable in all releases up through version 1. 0.6, inclusive, with unknown prior baseline. The plugin is a WordPress add‑on that provides front‑page splash screens for sites—any WordPress installation running these versions is affected. No official fix is currently published, so the vulnerability remains until bistromatic releases a patched version.

Risk and Exploitability

The CVSS score of 5.9 reflects moderate severity, and the EPSS score of less than 1% indicates that automated exploitation of this flaw is unlikely at present. The vulnerability is not catalogued in CISA’s KEV set. An attacker would need to supply content to the plugin’s input fields, which typically requires some level of user‑account access; once the malicious script is stored, it is served to all visitors. Because the flaw exploits a purely front‑end input validation weakness, it can be triggered without additional privileges, but the damage is limited to the affected site’s visitors.

Generated by OpenCVE AI on April 30, 2026 at 20:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for an updated release of N360 | Splash Screen from bistromatic; update the plugin if a fix is available.
  • If an upgrade cannot be applied immediately, disable or delete the plugin to stop the page rendering vulnerable content.
  • Audit existing splash screen content and remove any suspicious or encoded scripts that may have been stored prior to the update.

Generated by OpenCVE AI on April 30, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13734 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bistromatic N360 | Splash Screen allows Stored XSS. This issue affects N360 | Splash Screen: from n/a through 1.0.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bistromatic N360 | Splash Screen allows Stored XSS. This issue affects N360 | Splash Screen: from n/a through 1.0.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bistromatic N360 | Splash Screen n360-splash-screen allows Stored XSS.This issue affects N360 | Splash Screen: from n/a through <= 1.0.6.
Title WordPress N360 | Splash Screen <= 1.0.6 - Cross Site Scripting (XSS) Vulnerability WordPress N360 | Splash Screen plugin <= 1.0.6 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}

epss

{'score': 0.00042}


Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bistromatic N360 | Splash Screen allows Stored XSS. This issue affects N360 | Splash Screen: from n/a through 1.0.6.
Title WordPress N360 | Splash Screen <= 1.0.6 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:48.606Z

Reserved: 2025-05-07T10:45:20.229Z

Link: CVE-2025-47665

cve-icon Vulnrichment

Updated: 2025-05-07T17:18:59.848Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:16:18.907

Modified: 2026-04-23T15:30:42.430

Link: CVE-2025-47665

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T20:30:26Z

Weaknesses