Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashboard Beacon wp-dashboard-beacon allows Stored XSS.This issue affects Dashboard Beacon: from n/a through <= 1.2.0.
Published: 2025-12-31
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dashboard Beacon employs improper neutralization of input during page generation, creating a stored XSS flaw that allows attackers to embed malicious JavaScript that a victim’s browser will execute. As a result, an attacker can hijack sessions, exfiltrate data, deface content, or perform other client‑side attacks on anyone who views the infected page. The weakness is a classic input‑validation problem, labeled CWE‑79.

Affected Systems

The vulnerability exists in all releases of the WordPress plugin Dashboard Beacon from janhenckens up through version 1.2.0. No higher‑version releases are affected.

Risk and Exploitability

The CVSS score of 5.9 signals moderate severity, while the EPSS score of less than 1% indicates a low probability of widespread exploitation at present. The issue is not in CISA’s KEV catalog, suggesting no current large‑scale attacks. An attacker would first need to supply malicious content that the plugin stores and later displays, which likely requires some level of user privilege to add or edit such content, though the specific privilege level is not disclosed in the CVE description. Once stored, the payload will run in the browsers of all users who view the affected page, making it a risk for any site that enables such content submission.

Generated by OpenCVE AI on April 30, 2026 at 14:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dashboard Beacon to a version newer than 1.2.0 that contains the XSS fix.
  • If an update cannot be applied, disable or uninstall the plugin to eliminate the vulnerability.
  • Restrict which user roles can submit or edit content that feeds into the plugin, ensuring only trusted accounts have that capability.

Generated by OpenCVE AI on April 30, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashboard Beacon allows Stored XSS.This issue affects Dashboard Beacon: from n/a through 1.2.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashboard Beacon wp-dashboard-beacon allows Stored XSS.This issue affects Dashboard Beacon: from n/a through <= 1.2.0.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Janhenckens
Janhenckens dashboard Beacon
Wordpress
Wordpress wordpress
Vendors & Products Janhenckens
Janhenckens dashboard Beacon
Wordpress
Wordpress wordpress

Fri, 02 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashboard Beacon allows Stored XSS.This issue affects Dashboard Beacon: from n/a through 1.2.0.
Title WordPress Dashboard Beacon plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Janhenckens Dashboard Beacon
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:01.264Z

Reserved: 2025-06-04T09:42:27.086Z

Link: CVE-2025-49337

cve-icon Vulnrichment

Updated: 2026-01-02T14:20:18.586Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T18:15:44.173

Modified: 2026-04-23T15:31:29.613

Link: CVE-2025-49337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T14:30:06Z

Weaknesses