Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall image-wall allows Stored XSS.This issue affects Image Wall: from n/a through <= 3.1.
Published: 2025-07-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported flaw is an improper neutralization of user input during page rendering in the Parakoos Image Wall plugin, which results in a stored cross‑site scripting (XSS) vulnerability. The defect allows an attacker to inject malicious JavaScript into the plugin’s content area, which will execute in the browsers of any visitor to the infected page. Once injected, the attack can be used to hijack user sessions, steal cookies, deface the site, or redirect users to phishing pages.

Affected Systems

The vulnerability affects all releases of the Image Wall plugin up to and including version 3.1. The plugin is a WordPress add‑on developed by Parakoos and is typically deployed on publicly accessible websites that use WordPress as their CMS. No specific operating system or PHP version constraints are mentioned, so any site running a compatible WordPress installation with this plugin is potentially impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates medium to high severity, and the EPSS score of less than 1% suggests low yet non‑zero exploitation probability. The flaw is not yet listed in the CISA KEV catalog, but the stored nature of the XSS and the wide distribution of the plugin mean that an attacker could realistically exploit the weakness by submitting crafted content through the plugin’s interface or by leveraging another user’s ability to input data. The primary vector is client‑side execution driven by malicious content stored on the server.

Generated by OpenCVE AI on April 30, 2026 at 09:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Image Wall plugin to the latest version available (≥3.2) from the official WordPress plugin repository, which contains the proper input sanitization fix.
  • If an upgrade is not immediately possible, disable the plugin entirely or delete it from the site to prevent the vulnerability from being exploited.
  • While waiting for an update, enforce strict output escaping on any custom or user‑generated content handled by the plugin, or apply a web application firewall rule that blocks script injections in the plugin’s data fields.

Generated by OpenCVE AI on April 30, 2026 at 09:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21649 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall allows Stored XSS. This issue affects Image Wall: from n/a through 3.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall allows Stored XSS. This issue affects Image Wall: from n/a through 3.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall image-wall allows Stored XSS.This issue affects Image Wall: from n/a through <= 3.1.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 16 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00031}


Wed, 16 Jul 2025 10:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall allows Stored XSS. This issue affects Image Wall: from n/a through 3.1.
Title WordPress Image Wall plugin <= 3.1 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:52.836Z

Reserved: 2025-05-15T18:02:03.511Z

Link: CVE-2025-48156

cve-icon Vulnrichment

Updated: 2025-07-16T18:56:03.500Z

cve-icon NVD

Status : Deferred

Published: 2025-07-16T11:15:24.647

Modified: 2026-04-23T15:30:54.030

Link: CVE-2025-48156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:45:25Z

Weaknesses