Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad Awais WP Super Edit wp-super-edit allows Reflected XSS.This issue affects WP Super Edit: from n/a through <= 2.5.4.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Neutralization of Input During Web Page Generation that enables attackers to inject any HTML or JavaScript when the plugin processes user data. Because the WP Super Edit plugin does not sanitize reflected inputs, an attacker can craft a malicious URL or submit a form that will cause the victim’s browser to execute attacker‑controlled script. The impact is the ability to steal credentials, deface the site, or execute additional malicious actions in the context of the victim, without requiring any further privileges.

Affected Systems

The flaw exists in the Ahmad Awais WP Super Edit plugin for WordPress versions up to and including 2.5.4. Any WordPress site that has installed this version of the plugin is at risk. The specific vendor and product name can be found in the WordPress plugin repository, though no CPE strings are listed in the CVE data.

Risk and Exploitability

The CVSS base score of 7.1 signifies high severity. The EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not referenced in the CISA KEV catalog. The likely attack vector is a reflected XSS scenario, where an attacker crafts a malicious link or form that the plugin echoes back to a victim’s browser. An attacker would need to lure a user to the crafted URL or submit the malicious input, which typically requires social engineering in a web‑browser environment.

Generated by OpenCVE AI on April 29, 2026 at 16:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP Super Edit to version 2.5.5 or newer.
  • If an update is not immediately available, remove or disable the WP Super Edit plugin from the site.
  • Implement a Content Security Policy that blocks the execution of unexpected inline scripts for the affected domain.
  • Verify that all input fields of the plugin are properly sanitized before rendering.

Generated by OpenCVE AI on April 29, 2026 at 16:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad Awais WP Super Edit wp-super-edit allows Reflected XSS.This issue affects WP Super Edit: from n/a through <= 2.5.4.
Title WordPress WP Super Edit plugin <= 2.5.4 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:27:44.086Z

Reserved: 2025-06-11T16:07:27.324Z

Link: CVE-2025-49948

cve-icon Vulnrichment

Updated: 2025-10-23T14:33:59.763Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:41.107

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-49948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T16:45:15Z

Weaknesses