Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cynob IT Consultancy Auto Login After Registration auto-login-after-registration allows Reflected XSS.This issue affects Auto Login After Registration: from n/a through <= 1.0.0.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected XSS flaw as indicated. Based on the description, it is inferred that improper neutralization of user‑supplied input occurs when generating web pages by the Auto Login After Registration plugin. This allows an attacker to insert malicious scripts into the registration or auto‑login flow, causing them to execute in the context of any user who visits the vulnerable page. This can lead to session hijacking, data theft, or defacement without needing higher privileges on the site. The weakness is classified as CWE‑79.

Affected Systems

The flaw exists in the Auto Login After Registration plugin developed by Cynob IT Consultancy, affecting all releases from the first version up to and including 1.0.0. Any WordPress site that has this plugin installed is vulnerable, regardless of theme or other plugins.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact, while the EPSS score of less than 1% suggests that current exploitation probability is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires a user to visit a crafted URL or submit a tampered registration request, so it is a browser‑side reflected XSS requiring no authentication or privilege escalation. The likely attack vector is a crafted URL or tampered registration submission, exposing sites running an old plugin version until an update is applied.

Generated by OpenCVE AI on April 29, 2026 at 23:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Auto Login After Registration plugin to the latest version that addresses the XSS flaw, if one is available.
  • If an update is not yet released, immediately deactivate or uninstall the plugin to eliminate the attack surface.
  • Apply input sanitization or a content security policy to mitigate the reflected XSS risk in the registration workflow while awaiting an official fix.

Generated by OpenCVE AI on April 29, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cynob IT Consultancy Auto Login After Registration auto-login-after-registration allows Reflected XSS.This issue affects Auto Login After Registration: from n/a through <= 1.0.0.
Title WordPress Auto Login After Registration plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:27:23.488Z

Reserved: 2025-06-11T16:07:27.324Z

Link: CVE-2025-49946

cve-icon Vulnrichment

Updated: 2025-10-23T14:44:18.790Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:40.840

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-49946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')