Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kadesthemes WP Airdrop Manager airdrop allows Stored XSS.This issue affects WP Airdrop Manager: from n/a through <= 1.0.5.
Published: 2025-08-14
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Airdrop Manager plugin for WordPress contains a stored cross‑site scripting vulnerability that can be triggered by untrusted input. The flaw arises because the plugin does not properly neutralize user‑supplied data before rendering it in a page, allowing malicious JavaScript to be persisted and executed later. Attackers can leverage this to steal credentials, inject malware, or deface the site, compromising confidentiality and integrity of user sessions. The CVSS score of 5.9 indicates a moderate risk, and the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not present in the CISA KEV catalog. Inferred attack vector is via the plugin’s front‑end or admin interface, where an attacker can submit malicious input that will be rendered unescaped to other users. Mitigation is therefore time‑critical for sites that rely on XSS for malicious payloads.

Affected Systems

The vulnerability impacts all WordPress sites that have installed the kadesthemes WP Airdrop Manager plugin version 1.0.5 or earlier. The affected product is the plugin itself, and any WordPress installation incorporating this version is susceptible.

Risk and Exploitability

The CVSS score of 5.9 signals a moderate severity, while the EPSS value of less than 1% indicates low probability of exploitation at present. The vulnerability has not been flagged in the CISA KEV catalog. Based on the description, the likely attack vector is through user‑controllable input rendered on the site, enabling attackers to inject persistent scripts that will execute in the browsers of other visitors.

Generated by OpenCVE AI on May 1, 2026 at 06:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Airdrop Manager to the latest available version to address the stored XSS flaw.
  • If an immediate upgrade is not possible, disable all input fields that accept unsanitized data or place the plugin in a read‑only mode to prevent new payloads from being stored.
  • Deploy a content security policy that blocks or restricts execution of inline scripts from the plugin’s output, reducing the impact of any remaining or future XSS vectors.

Generated by OpenCVE AI on May 1, 2026 at 06:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24761 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kadesthemes WP Airdrop Manager allows Stored XSS. This issue affects WP Airdrop Manager: from n/a through 1.0.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kadesthemes WP Airdrop Manager allows Stored XSS. This issue affects WP Airdrop Manager: from n/a through 1.0.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kadesthemes WP Airdrop Manager airdrop allows Stored XSS.This issue affects WP Airdrop Manager: from n/a through <= 1.0.5.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Thu, 14 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 10:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kadesthemes WP Airdrop Manager allows Stored XSS. This issue affects WP Airdrop Manager: from n/a through 1.0.5.
Title WordPress WP Airdrop Manager plugin <= 1.0.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:32:41.245Z

Reserved: 2025-05-30T14:04:34.998Z

Link: CVE-2025-49053

cve-icon Vulnrichment

Updated: 2025-08-14T15:12:00.862Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T11:15:37.517

Modified: 2026-04-23T15:31:14.740

Link: CVE-2025-49053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T07:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')