Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in worstguy WP LOL Rotation league-of-legends-rotation allows Stored XSS.This issue affects WP LOL Rotation: from n/a through <= 1.0.
Published: 2025-08-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP LOL Rotation plugin version 1.0 or earlier contains an Improper Neutralization of Input During Web Page Generation vulnerability. This stored XSS flaw allows an attacker to inject arbitrary scripts that are later rendered to the browser of any user who views the affected content. If executed, the script runs with the privileges of that user, potentially hijacking sessions, collecting credentials, or defacing the site, thereby compromising confidentiality, integrity, and availability of site data. The weakness maps to CWE-79 and is limited to encoded or stored input that is not properly escaped before display.

Affected Systems

This issue affects the WordPress plugin WP LOL Rotation developed by worstguy. All installations of the plugin from the earliest available version up through and including 1.0 are vulnerable. No further version range is specified; therefore any legacy installation of this plugin without an upgrade is considered at risk.

Risk and Exploitability

The CVSS score for this vulnerability is 6.5, indicating moderate severity. The EPSS score is less than 1%, indicating a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the plugin’s admin interface or content entry points where an attacker can supply malicious input that will be stored and later rendered to users. Once the payload is embedded in the page, any user who views that page will have the script executed in their browser. Because the impact is confined to the browser context and requires the attacker to be able to inject data, the overall risk is moderate but higher if the plugin is used on public-facing sites where users can be forwarded to vulnerable pages.

Generated by OpenCVE AI on April 30, 2026 at 09:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Remove or disable the WP LOL Rotation plugin if it is no longer required or cannot be updated.
  • Upgrade the plugin to the latest version that contains a fix for the stored XSS flaw.
  • If removal or upgrade is not possible, apply proper output encoding to all plugin fields that display user data, and consider deploying a web application firewall that blocks XSS payloads.

Generated by OpenCVE AI on April 30, 2026 at 09:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24776 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in worstguy WP LOL Rotation allows Stored XSS. This issue affects WP LOL Rotation: from n/a through 1.0.
History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in worstguy WP LOL Rotation allows Stored XSS. This issue affects WP LOL Rotation: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in worstguy WP LOL Rotation league-of-legends-rotation allows Stored XSS.This issue affects WP LOL Rotation: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 14 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 10:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in worstguy WP LOL Rotation allows Stored XSS. This issue affects WP LOL Rotation: from n/a through 1.0.
Title WordPress WP LOL Rotation <= 1.0 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:55.313Z

Reserved: 2025-06-04T15:44:46.228Z

Link: CVE-2025-49437

cve-icon Vulnrichment

Updated: 2025-08-14T16:00:16.009Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T11:15:40.423

Modified: 2026-04-29T10:16:48.560

Link: CVE-2025-49437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:15:28Z

Weaknesses