Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Perdaan WC MyParcel Belgium allows Reflected XSS. This issue affects WC MyParcel Belgium: from 4.5.5 through beta.
Published: 2025-06-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the WordPress WC MyParcel Belgium plugin allows reflected cross‑site scripting via improper neutralization of input during web page generation. If an attacker supplies malicious data that the plugin outputs without adequate escaping, the payload can execute in the browser of any user who views the affected page, enabling session theft, defacement, or redirection.

Affected Systems

The vulnerability affects the WC MyParcel Belgium plugin developed by Richard Perdaan. Versions 4.5.5 and the 4.5.5-beta release are impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, but the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA's KEV catalog, and no publicly known active exploits have been reported. Likely attack vectors involve a crafted URL or form that the plugin renders; the exploit requires the attacker to entice a victim to visit the URL, making it a typical reflected XSS scenario.

Generated by OpenCVE AI on May 1, 2026 at 07:40 UTC.

Remediation

Vendor Solution

Update the WordPress WC MyParcel Belgium plugin to the latest available version (at least 4.5.6).


OpenCVE Recommended Actions

  • Update the WordPress WC MyParcel Belgium plugin to version 4.5.6 or later.
  • Remove or replace any older references to the plugin in the site configuration to prevent accidental reload of vulnerable code.
  • Sanitize all user‑controlled input that the plugin echoes by applying escaping functions such as wp_kses() or esc_html() to mitigate remaining XSS risk.

Generated by OpenCVE AI on May 1, 2026 at 07:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17538 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Perdaan WC MyParcel Belgium allows Reflected XSS. This issue affects WC MyParcel Belgium: from 4.5.5 through beta.
History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Perdaan WC MyParcel Belgium wc-myparcel-belgium allows Reflected XSS.This issue affects WC MyParcel Belgium: from n/a through <= 4.5.5-beta. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Perdaan WC MyParcel Belgium allows Reflected XSS. This issue affects WC MyParcel Belgium: from 4.5.5 through beta.
References

Thu, 23 Apr 2026 15:45:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Perdaan WC MyParcel Belgium allows Reflected XSS. This issue affects WC MyParcel Belgium: from 4.5.5 through beta. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Perdaan WC MyParcel Belgium wc-myparcel-belgium allows Reflected XSS.This issue affects WC MyParcel Belgium: from n/a through <= 4.5.5-beta.
References

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}

epss

{'score': 0.00039}


Mon, 09 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Perdaan WC MyParcel Belgium allows Reflected XSS. This issue affects WC MyParcel Belgium: from 4.5.5 through beta.
Title WordPress WC MyParcel Belgium plugin <= 4.5.5-beta - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:55.352Z

Reserved: 2025-05-19T14:13:24.502Z

Link: CVE-2025-48279

cve-icon Vulnrichment

Updated: 2025-06-09T19:22:39.082Z

cve-icon NVD

Status : Deferred

Published: 2025-06-09T16:15:44.490

Modified: 2026-04-28T19:32:42.653

Link: CVE-2025-48279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T07:45:06Z

Weaknesses